← Back
CWE-209

607 CVEs • Abstraction: Base • Likelihood of Exploit: High

Generation of Error Message Containing Sensitive Information

The product generates an error message that includes sensitive information about its environment, users, or associated data.

JSON object

Loading...

CVEs (607)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gitlab
1Gitlab
Jun 17, 2026
Apr 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure.
1Auth0
1Auth0 Wcf Service Jwt
Jun 17, 2026
Apr 11, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT signature. If this error message is presented to an attacker, they can forge an a...Show more
Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT signature. If this error message is presented to an attacker, they can forge an arbitrary JWT token that will be accepted by the vulnerable application.Show less
2Elastic
Netapp
2Active Iq Performance Analytics Services
Logstash
Jun 17, 2026
Mar 25, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified as part of the Logstash configuration, the credentials for the URL coul...Show more
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified as part of the Logstash configuration, the credentials for the URL could be inadvertently logged as part of the error message.Show less
1Dropbear Ssh Project
1Dropbear Ssh
Nov 21, 2024
Mar 21, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the max...Show more
It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the maximum allowed number of password attempts.Show less
1Jforum
1Jforum
Jun 17, 2026
Feb 12, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JForum 2.1.8, an unauthenticated, remote attacker can enumerate whether a user exists by using the "create user" function. If a register/check/username?username= request corresponds to a username that exists, then an...Show more
In JForum 2.1.8, an unauthenticated, remote attacker can enumerate whether a user exists by using the "create user" function. If a register/check/username?username= request corresponds to a username that exists, then an "is already in use" error is produced. NOTE: this product is discontinued.Show less
1Theforeman
1Katello
Nov 21, 2024
Dec 14, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs. This is issue is...Show more
A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs. This is issue is related to an incomplete fix for CVE-2016-3072. Version 3.10 and older is vulnerable.Show less
4Artifex
CanonicalDebian+1 more
9Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+6 more
Nov 21, 2024
Oct 15, 2018
N/A· v4
8.6 HIGH· v3
6.8 MEDIUM· v2
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this issue exists because of an incomplete fix for CVE-2018-17183.
1Carestream
1Carestream Vue Ris
Nov 21, 2024
Oct 4, 2018
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
Carestream Vue RIS, RIS Client Builds: Version 11.2 and prior running on a Windows 8.1 machine with IIS/7.5. When contacting a Carestream server where there is no Oracle TNS listener available, users will trigger an HTTP...Show more
Carestream Vue RIS, RIS Client Builds: Version 11.2 and prior running on a Windows 8.1 machine with IIS/7.5. When contacting a Carestream server where there is no Oracle TNS listener available, users will trigger an HTTP 500 error, leaking technical information an attacker could use to initiate a more elaborate attack.Show less
4Debian
GlusterOpensuse+1 more
5Debian Linux
Enterprise Linux ServerGlusterfs+2 more
Nov 21, 2024
Sep 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine the existence of any file.
1Matera
1Banco
Nov 21, 2024
Aug 3, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Matera Banco 1.0.0 mishandles Java errors in the backend, as demonstrated by a stack trace revealing use of net.sf.acegisecurity components.
13cx
13cx Web Server
Nov 21, 2024
Aug 3, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Web server in 3CX version 15.5.8801.3 is vulnerable to Information Leakage, because of improper error handling in Stack traces, as demonstrated by discovering a full pathname.
1Johnsoncontrols
2Bcpro
Metasys System
Nov 21, 2024
Aug 1, 2018
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could all...Show more
In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to obtain technical information.Show less
1Apache
1Ambari
Jun 17, 2026
Jul 18, 2018
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Apache Ambari, version 2.5.0 to 2.6.2, passwords for Hadoop credential stores are exposed in Ambari Agent informational log messages when the credential store feature is enabled for eligible services. For example, Hive a...Show more
Apache Ambari, version 2.5.0 to 2.6.2, passwords for Hadoop credential stores are exposed in Ambari Agent informational log messages when the credential store feature is enabled for eligible services. For example, Hive and Oozie.Show less
2Eclipse
Oracle
2Jetty
Retail Xstore Point Of Service
Nov 21, 2024
Jun 27, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handled by the DefaultServl...Show more
In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handled by the DefaultServlet's static file serving, the bad characters can trigger a java.nio.file.InvalidPathException which includes the full path to the base resource directory that the DefaultServlet and/or webapp is using. If this InvalidPathException is then handled by the default Error Handler, the InvalidPathException message is included in the error response, revealing the full server path to the requesting system.Show less
2Ovirt
Redhat
3Ovirt Engine
VirtualizationVirtualization Host
Nov 21, 2024
Jun 19, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts.
1Joomla
1Joomla
Nov 21, 2024
May 22, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after either a form validation error or navigating to a previous install step, and display the plaintext pa...Show more
An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after either a form validation error or navigating to a previous install step, and display the plaintext password for the administrator account at the confirmation screen.Show less
1Hawt
1Hawtio
Nov 21, 2024
May 8, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
hawtio before versions 2.0-beta-1, 2.0-beta-2 2.0-m1, 2.0-m2, 2.0-m3, and 1.5 is vulnerable to a path traversal that leads to a NullPointerException with a full stacktrace. An attacker could use this flaw to gather undis...Show more
hawtio before versions 2.0-beta-1, 2.0-beta-2 2.0-m1, 2.0-m2, 2.0-m3, and 1.5 is vulnerable to a path traversal that leads to a NullPointerException with a full stacktrace. An attacker could use this flaw to gather undisclosed information from within hawtio's root.Show less
1Sap
1Hana Extended Application Services
Nov 21, 2024
Feb 14, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evaluating error messages of a specific endpoint.
1Fedoraproject
1389 Directory Server
May 13, 2026
Aug 16, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on password attempts.
1Ibm
1Jazz Reporting Service
May 13, 2026
Jul 31, 2017
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user credentials, through an error message from the Report Builder administrator configuration page. IBM X-Force ID: 126863.