CWE-209
575 CVEs • Abstraction: Base • Likelihood of Exploit: High
Generation of Error Message Containing Sensitive Information
The product generates an error message that includes sensitive information about its environment, users, or associated data.
CVEs (575)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Apache Ambari, version 2.5.0 to 2.6.2, passwords for Hadoop credential stores are exposed in Ambari Agent informational log messages when the credential store feature is enabled for eligible services. For example, Hive a...Show more |
2Eclipse Oracle2Jetty Retail Xstore Point Of ServiceNov 21, 2024 Jun 27, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handled by the DefaultServl...Show more |
2Ovirt Redhat3Ovirt Engine VirtualizationVirtualization HostNov 21, 2024 Jun 19, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts. |
An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after either a form validation error or navigating to a previous install step, and display the plaintext pa...Show more |
hawtio before versions 2.0-beta-1, 2.0-beta-2 2.0-m1, 2.0-m2, 2.0-m3, and 1.5 is vulnerable to a path traversal that leads to a NullPointerException with a full stacktrace. An attacker could use this flaw to gather undis...Show more |
1Sap 1Hana Extended Application Services Nov 21, 2024 Feb 14, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evaluating error messages of a specific endpoint. |
1Fedoraproject 1389 Directory Server May 13, 2026 Aug 16, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on password attempts. |
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user credentials, through an error message from the Report Builder administrator configuration page. IBM X-Force ID: 126863. |
The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, 7.1.x before 7.1.9, and 8.x before 8.0.2 provides different error messages for failed login attempts depending on whethe...Show more |
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with access to a write-only share may enumera...Show more |
2Nextcloud Owncloud2Nextcloud Server OwncloudMay 13, 2026 Mar 28, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a log pollution vulnerability potentially leading to a local XSS. The download log functionality in the admin screen is delivering the log i...Show more |
1Microsoft 1Internet Explorer Apr 22, 2026 Feb 26, 2014 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet hostnames, and intranet IP addresses by exami...Show more |
1Redhat 2Network Proxy SatelliteApr 29, 2026 Feb 5, 2014 N/A· v4 4.9 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in Spacewalk-backend. This information disclosure vulnerability occurs when a system registration XML-RPC call fails, causing cleartext user passwords to be included in error messages. Remote administrat...Show more |
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allow...Show more |
htsearch program in htDig 3.2 beta, 3.1.6, 3.1.5, and earlier allows remote attackers to determine the physical path of the server by requesting a non-existent configuration file using the config parameter, which generat...Show more |