CWE-209— Generation of Error Message Containing Sensitive Information
535 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-209page 6 of 11
- CVE-2022-40292MEDIUMCVSS 5.3EG 5.32022-10-31
The application allowed for Unauthenticated User Enumeration by interacting with an unsecured endpoint to retrieve information on each account within the system.
- CVE-2022-43891LOWCVSS 2.7EG 2.72023-10-17
IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against th…
- CVE-2022-46371MEDIUMCVSS 5.3EG 5.32023-01-12
Alotcer - AR7088H-A firmware version 16.10.3 Information disclosure. Unspecified error message contains the default administrator user name.
- CVE-2022-46675MEDIUMCVSS 5.3EG 5.32023-02-11
Wyse Management Suite Repository 3.8 and below contain an information disclosure vulnerability. A unauthenticated attacker could potentially discover the internal structure of the application and its components and use this information fo…
- CVE-2022-4769MEDIUMCVSS 4.3EG 4.32023-04-03
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the target path on host when a file is uploaded with an invalid character in its name.
- CVE-2022-4770MEDIUMCVSS 4.3EG 4.32023-04-03
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the full parametrized SQL query in an error message when an invalid character is used within a Pentaho Report (*.prpt).
- CVE-2022-4870MEDIUMCVSS 5.3EG 5.32023-05-18
In affected versions of Octopus Deploy it is possible to discover network details via error message
- CVE-2022-50686HIGHCVSS 7.5EG 5.32025-12-18
An information disclosure vulnerability in Kentico Xperience allows attackers to view sensitive stack trace details via Portal Engine form control error messages. Detailed error messages can expose internal system information and potential…
- CVE-2023-0655MEDIUMCVSS 5.3EG 5.32023-02-14
SonicWall Email Security contains a vulnerability that could permit a remote unauthenticated attacker access to an error page that includes sensitive information about users email addresses.
- CVE-2023-0833MEDIUMCVSS 4.7EG 4.72023-09-27
A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception triggered by a header containing an illegal value. This issue could allow an authenticated attack…
- CVE-2023-1210LOWCVSS 3.1EG 3.12023-08-02
An issue has been discovered in GitLab affecting all versions starting from 12.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to leak a user's email via an err…
- CVE-2023-20593MEDIUMCVSS 5.5EG 5.52023-07-24
An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.
- CVE-2023-21103MEDIUMCVSS 5.5EG 5.52023-05-15
In registerPhoneAccount of PhoneAccountRegistrar.java, uncaught exceptions in parsing persisted user data could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for e…
- CVE-2023-22626HIGHCVSS 7.5EG 7.52023-01-05
PgHero before 3.1.0 allows Information Disclosure via EXPLAIN because query results may be present in an error message. (Depending on database user privileges, this may only be information from the database, or may be information from file…
- CVE-2023-23474LOWCVSS 3.7EG 3.72024-05-03
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 245403.
- CVE-2023-23837HIGHCVSS 7.5EG 4.32023-04-25
No exception handling vulnerability which revealed sensitive or excessive information to users.
- CVE-2023-25687MEDIUMCVSS 4.3EG 4.32023-03-21
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to obtain sensitive information from log files. IBM X-Force ID: 247602.
- CVE-2023-25695MEDIUMCVSS 5.3EG 5.32023-03-15
Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.5.2.
- CVE-2023-25948HIGHCVSS 7.5EG 7.52023-07-13
Server information leak of configuration data when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.
- CVE-2023-25956HIGHCVSS 7.5EG 7.52023-02-24
Generation of Error Message Containing Sensitive Information vulnerability in the Apache Airflow AWS Provider. This issue affects Apache Airflow AWS Provider versions before 7.2.1.
- CVE-2023-26051MEDIUMCVSS 6.5EG 6.52023-03-02
Saleor is a headless, GraphQL commerce platform delivering personalized shopping experiences. Some internal Python exceptions are not handled properly and thus are returned in API as error messages. Some messages might contain sensitive in…
- CVE-2023-26052LOWCVSS 3.7EG 3.72023-03-02
Saleor is a headless, GraphQL commerce platform delivering personalized shopping experiences. Some internal Python exceptions are not handled properly and thus are returned in API as error messages. Some messages might contain sensitive in…
- CVE-2023-26272MEDIUMCVSS 5.3EG 5.32023-08-28
IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could…
- CVE-2023-27319MEDIUMCVSS 5.3EG 5.32023-12-21
ONTAP Mediator versions prior to 1.7 are susceptible to a vulnerability that can allow an unauthenticated attacker to enumerate URLs via REST API.
- CVE-2023-27587HIGHCVSS 7.4EG 7.42023-03-13
ReadtoMyShoe, a web app that lets users upload articles and listen to them later, generates an error message containing sensitive information prior to commit 8533b01. If an error occurs when adding an article, the website shows the user an…
- CVE-2023-27860MEDIUMCVSS 5.3EG 5.32023-04-27
IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could disclose sensitive information in an error message. This information could be used in further attacks against the system. IBM X-Force ID: 249207.
- CVE-2023-28117HIGHCVSS 7.6EG 7.62023-03-22
Sentry SDK is the official Python SDK for Sentry, real-time crash reporting software. When using the Django integration of versions prior to 1.14.0 of the Sentry SDK in a specific configuration it is possible to leak sensitive cookies valu…
- CVE-2023-28514MEDIUMCVSS 6.2EG 6.22023-05-19
IBM MQ 8.0, 9.0, and 9.1 could allow a local user to obtain sensitive credential information when a detailed technical error message is returned in a stack trace. IBM X-Force ID: 250398.
- CVE-2023-29193HIGHCVSS 8.7EG 8.72023-04-14
SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing security-critical application permissions. The `spicedb serve` command contains a flag named `--grpc-preshared-key` which is used to protect the…
- CVE-2023-31048MEDIUMCVSS 5.3EG 5.32023-12-12
The OPC UA .NET Standard Reference Server before 1.4.371.86. places sensitive information into an error message that may be seen remotely.
- CVE-2023-31286MEDIUMCVSS 5.3EG 5.32023-04-27
An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When a password reset request occurs, the server response leaks the existence of users. If one tries to reset a password of a non-existent user, an error message ind…
- CVE-2023-31429MEDIUMCVSS 5.5EG 5.52023-08-01
Brocade Fabric OS before Brocade Fabric OS 9.1.1c, 9.2.0 contains a vulnerability when using various commands such as “chassisdistribute”, “reboot”, “rasman”, errmoduleshow, errfilterset, hassiscfgperrthreshold, supportshowcfgd…
- CVE-2023-32755MEDIUMCVSS 5.3EG 5.32023-08-25
e-Excellence U-Office Force generates an error message in webiste service. An unauthenticated remote attacker can obtain partial sensitive system information from error message by sending a crafted command.
- CVE-2023-33181MEDIUMCVSS 4.3EG 4.32023-05-30
Xibo is a content management system (CMS). Starting in version 3.0.0 and prior to version 3.3.5, some API routes will print a stack trace when called with missing or invalid parameters revealing sensitive information about the locations of…
- CVE-2023-3362MEDIUMCVSS 5.3EG 5.32023-07-13
An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error information if a project was imported from GitHub.
- CVE-2023-33834MEDIUMCVSS 4.3EG 4.32023-08-31
IBM Security Verify Information Queue 10.0.4 and 10.0.5 could allow a remote attacker to obtain sensitive information that could aid in further attacks against the system. IBM X-force ID: 256014.
- CVE-2023-33835MEDIUMCVSS 4.3EG 4.32023-08-31
IBM Security Verify Information Queue 10.0.4 and 10.0.5 could allow a remote attacker to obtain sensitive information that could aid in further attacks against the system. IBM X-Force ID: 256015.
- CVE-2023-34110LOWCVSS 2.7EG 2.72023-06-22
Flask-AppBuilder is an application development framework, built on top of Flask. Prior to version 4.3.2, an authenticated malicious actor with Admin privileges, could by adding a special character on the add, edit User forms trigger a data…
- CVE-2023-34339LOWCVSS 3.3EG 3.32023-06-01
In JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's message
- CVE-2023-35009MEDIUMCVSS 5.3EG 5.32023-08-16
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a remote attacker to obtain system information without authentication which could be used in reconnaissance to gather information that could be used for future attacks. IBM X-For…
- CVE-2023-35124LOWCVSS 3.1EG 3.12023-09-05
An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to a disclosure of sensit…
- CVE-2023-37260HIGHCVSS 8.2EG 8.22023-07-06
league/oauth2-server is an implementation of an OAuth 2.0 authorization server written in PHP. Starting in version 8.3.2 and prior to version 8.5.3, servers that passed their keys to the CryptKey constructor as as string instead of a file …
- CVE-2023-37306HIGHCVSS 7.5EG 7.52023-06-30
MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.
- CVE-2023-37489MEDIUMCVSS 5.3EG 5.32023-09-12
Due to the lack of validation, SAP BusinessObjects Business Intelligence Platform (Version Management System) - version 403, permits an unauthenticated user to read the code snippet through the UI, which leads to low impact on confidential…
- CVE-2023-38010MEDIUMCVSS 5.3EG 5.32026-02-04
IBM Cloud Pak System displays sensitive information in user messages that could aid in further attacks against the system.
- CVE-2023-38017MEDIUMCVSS 5.3EG 5.32026-02-04
IBM Cloud Pak System is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a t…
- CVE-2023-38281MEDIUMCVSS 5.3EG 5.32026-02-04
IBM Cloud Pak System does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The …
- CVE-2023-38713MEDIUMCVSS 5.3EG 5.32025-01-25
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information about the system that could aid in further attacks against the …
- CVE-2023-38714MEDIUMCVSS 5.3EG 5.32025-01-25
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information about the system that could aid in further attacks against the …
- CVE-2023-38716MEDIUMCVSS 5.3EG 5.32025-01-25
IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0 could disclose sensitive information about the system that could aid in further attacks against the system.
Map vulnerabilities like CWE-209 to your infrastructure
EchelonGraph correlates every CVE — across CWE-209 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →