← Back
CWE-209

607 CVEs • Abstraction: Base • Likelihood of Exploit: High

Generation of Error Message Containing Sensitive Information

The product generates an error message that includes sensitive information about its environment, users, or associated data.

JSON object

Loading...

CVEs (607)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gitlab
1Gitlab
Jun 17, 2026
Sep 9, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Path Disclosure. When an error is encountered on project import, the error messa...Show more
An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Path Disclosure. When an error is encountered on project import, the error message will display instance internal information.Show less
1Senecajs
1Seneca
Jun 17, 2026
Sep 9, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Seneca < 3.9.0 contains a vulnerability that could lead to exposing environment variables to unauthorized users.
1Silver Peak
1Unity Edgeconnect Sd Wan Firmware
Jun 17, 2026
Sep 8, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to obtain potentially sensitive stack traces by sending incorrect JSON data to the REST API, such as the rest/json/banners URI.
2Google
Opensuse
2Android
Leap
Jun 17, 2026
Sep 6, 2019
N/A· v4
2.3 LOW· v3
2.1 LOW· v2
In the Android kernel in the video driver there is a kernel pointer leak due to a WARN_ON statement. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed...Show more
In the Android kernel in the video driver there is a kernel pointer leak due to a WARN_ON statement. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Show less
1Bosch
2Iot Gateway Software
Prosyst Mbs Sdk
Jun 17, 2026
Aug 21, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Leakage of stack traces in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.2.0 allows remote attackers to gather information about the file system structu...Show more
Leakage of stack traces in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.2.0 allows remote attackers to gather information about the file system structure.Show less
1Ibm
3Emptoris Contract Management
Emptoris SourcingEmptoris Spend Analysis
Jun 17, 2026
Aug 20, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 generates an error message that includes sensitive information that could...Show more
IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164069.Show less
1Ibm
3Emptoris Contract Management
Emptoris SourcingEmptoris Spend Analysis
Jun 17, 2026
Aug 20, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 generates an error message that includes sensitive information that could...Show more
IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164068.Show less
1Ibm
3Intelligent Operations Center
Intelligent Operations Center For Emergency ManagementWater Operations For Waternamics
Jun 17, 2026
Aug 20, 2019
N/A· v4
6.2 MEDIUM· v3
2.1 LOW· v2
IBM Intelligent Operations Center V5.1.0 through V5.2.0 could disclose detailed error messages, revealing sensitive information that could aid in further attacks against the system. IBM X-Force ID: 162738.
1Ibm
3Emptoris Contract Management
Emptoris SourcingEmptoris Spend Analysis
Jun 17, 2026
Aug 20, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 could allow an authenticated user to obtain sensitive information from err...Show more
IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 could allow an authenticated user to obtain sensitive information from error messages IBM X-Force ID: 161034.Show less
4Canonical
DebianOpenstack+1 more
4Debian Linux
NovaOpenstack+1 more
Jun 17, 2026
Aug 9, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the un...Show more
An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.Show less
1Parseplatform
1Parse Server
Jun 17, 2026
Jul 29, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
parse-server before 3.6.0 allows account enumeration.
1Adobe
1Campaign
Jun 17, 2026
Jul 18, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Information Exposure Through an Error Message vulnerability. Successful exploitation could lead to Information Disclosure in the context of the cur...Show more
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Information Exposure Through an Error Message vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.Show less
1Ibm
1Spectrum Protect Operations Center
Jun 17, 2026
Jul 2, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote attacker to obtain sensitive information, caused by an error message containing a stack trace. By creating an error with a stack trace, an attacker...Show more
IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote attacker to obtain sensitive information, caused by an error message containing a stack trace. By creating an error with a stack trace, an attacker could exploit this vulnerability to potentially obtain details on the Operations Center architecture. IBM X-Force ID: 158279.Show less
1Ibm
1Websphere Application Server
Jun 17, 2026
Jun 28, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console could allow a remote attacker to obtain sensitive information when a specially crafted url causes a stack trace to be dumped. IBM X-Force ID: 160202.
1Ibm
1Sterling B2b Integrator
Jun 17, 2026
Jun 25, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 reveals sensitive information from a stack trace that could be used in further attacks against the system. IBM X-Force ID: 162803.
1Pydio
1Cells
Jun 17, 2026
Jun 20, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Pydio Cells before 1.5.0, when supplied with a Name field in an unexpected Unicode format, fails to handle this and includes the database column/table name as pert of the error message, exposing sensitive information.
1Ibm
3Infosphere Information Analyzer
Infosphere Information Governance CatalogInfosphere Information Server On Cloud
Jun 17, 2026
Jun 6, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM InfoSphere Information Server 11.5 and 11.7 is affected by an information disclosure vulnerability. Sensitive information in an error message may be used to conduct further attacks against the system. IBM X-Force ID:...Show more
IBM InfoSphere Information Server 11.5 and 11.7 is affected by an information disclosure vulnerability. Sensitive information in an error message may be used to conduct further attacks against the system. IBM X-Force ID: 159945.Show less
1Ibm
1Security Information Queue
Jun 17, 2026
Jun 6, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 159228.
1Gnu
1Gcc
Nov 21, 2024
May 22, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumstances) generate instruction sequences when targeting ARM targets that s...Show more
stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumstances) generate instruction sequences when targeting ARM targets that spill the address of the stack protector guard, which allows an attacker to bypass the protection of -fstack-protector, -fstack-protector-all, -fstack-protector-strong, and -fstack-protector-explicit against stack overflow by controlling what the stack canary is compared against.Show less
1Matomo
1Matomo
Jun 17, 2026
May 20, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A full path disclosure vulnerability was discovered in Matomo v3.9.1 where a user can trigger a particular error to discover the full path of Matomo on the disk, because lastError.file is used in plugins/CorePluginsAdmin...Show more
A full path disclosure vulnerability was discovered in Matomo v3.9.1 where a user can trigger a particular error to discover the full path of Matomo on the disk, because lastError.file is used in plugins/CorePluginsAdmin/templates/safemode.twig. NOTE: the vendor disputes the significance of this issue, stating "avoid reporting path disclosures, as we don't consider them as security vulnerabilities.Show less