CWE-497
351 CVEs • Abstraction: Base
Exposure of Sensitive System Information to an Unauthorized Control Sphere
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.
CVEs (351)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in VaultDweller Leyka leyka.This issue affects Leyka: from n/a through <= 3.31.6. |
A vulnerability in Cortex XSOAR allows the disclosure of incident data to users who do not have the privilege to view the data. |
An issue was discovered in GitLab-CE/EE affecting all versions starting with 17.0 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. An attacker as a guest user was able to access commit information via the relea...Show more |
1Paloaltonetworks 3Globalprotect Pan OsPrisma AccessJun 17, 2026 Sep 11, 2024 6.9 MEDIUM· v4 7.1 HIGH· v3 N/A· v2 An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconn...Show more |
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 could disclose sensitive information in the HTTP response using man in the middle techniques. IBM X-Force ID: 265507. |
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 displays version information in HTTP requests that could allow an attacker to gather information for future attacks against the system. IBM X-Force ID: 296009...Show more |
A vulnerability has been identified in RUGGEDCOM RMC30 (All versions < V4.3.10), RUGGEDCOM RMC30NC (All versions < V4.3.10), RUGGEDCOM RP110 (All versions < V4.3.10), RUGGEDCOM RP110NC (All versions < V4.3.10), RUGGEDCOM...Show more |
Fides is an open-source privacy engineering platform, and `SERVER_SIDE_FIDES_API_URL` is a server-side configuration environment variable used by the Fides Privacy Center to communicate with the Fides webserver backend....Show more |
1Admiror Design Studio 1Admirorframes Jun 17, 2026 Jun 28, 2024 6.3 MEDIUM· v4 7.5 HIGH· v3 N/A· v2 Full Path Disclosure vulnerability in AdmirorFrames Joomla! extension in afHelper.php script allows an unauthorised attacker to retrieve location of web root folder. This issue affects AdmirorFrames: before 5.0. |
1Canonical 1Ubuntu Advantage Desktop Daemon Jun 17, 2026 Jun 27, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext. |
netplan leaks the private key of wireguard to local users. Versions after 1.0 are not affected. |
1Abb 52tma310010b0001 Firmware 2tma310010b0003 Firmware2tma310011b0001 Firmware+2 moreJun 17, 2026 Jun 5, 2024 7.3 HIGH· v4 8.8 HIGH· v3 N/A· v2 FDSK Leak in ABB, Busch-Jaeger, FTS Display (version 1.00) and BCU (version 1.3.0.33) allows attacker to take control via access to local KNX Bus-System |
tine before 2023.11.8, when an LDAP backend is used, allows anonymous remote attackers to obtain sensitive authentication information via setup.php because of getRegistryData in Setup/Frontend/Json.php. (An update is als...Show more |
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiADC version 7.4.1 and below, version 7.2.3 and below, version 7.1.4 and below, version 7.0.5 and below, versio...Show more |
1Analytify 1Analytify Google Analytics Dashboard Jun 17, 2026 May 2, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on AJAX functions in combination with...Show more |
1Ibm 1Security Verify Privilege On Premises Jun 17, 2026 Apr 16, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 IBM Security Verify Privilege 11.6.25 could allow an unauthenticated actor to obtain sensitive information from the SOAP API. IBM X-Force ID: 287651. |
aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restrictions on a specific parameter, allowing attackers to modify this parameter to access certain sensitive s...Show more |
A valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoint to retrieve system event information.
|
An information disclosure flaw was found in OpenShift Virtualization. The DownwardMetrics feature was introduced to expose host metrics to virtual machine guests and is enabled by default. This issue could expose limited...Show more |
1Ibm 1Cloud Pak For Business Automation Jun 17, 2026 Mar 31, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2,19.0.1, 19.0.2, 19.0.3,20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1,2 2.0.2, 23.0.1, and 23.0.2 may allow end users to query more documents than expe...Show more |