Filtered by CWE-209
Total 533 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-23837 2 Microsoft, Solarwinds 2 Windows, Database Performance Analyzer 2025-02-04 7.5 High
No exception handling vulnerability which revealed sensitive or excessive information to users.
CVE-2023-27860 1 Ibm 1 Maximo Asset Management 2025-01-30 5.3 Medium
IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could disclose sensitive information in an error message. This information could be used in further attacks against the system. IBM X-Force ID: 249207.
CVE-2024-36375 1 Jetbrains 1 Teamcity 2025-01-27 5.3 Medium
In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposed
CVE-2025-24552 2025-01-24 5.3 Medium
Generation of Error Message Containing Sensitive Information vulnerability in David de Boer Paytium allows Retrieve Embedded Sensitive Data. This issue affects Paytium: from n/a through 4.4.11.
CVE-2023-21103 1 Google 1 Android 2025-01-24 5.5 Medium
In registerPhoneAccount of PhoneAccountRegistrar.java, uncaught exceptions in parsing persisted user data could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-259064622
CVE-2022-4870 1 Octopus 1 Octopus Server 2025-01-21 5.3 Medium
In affected versions of Octopus Deploy it is possible to discover network details via error message
CVE-2024-13536 2025-01-21 5.3 Medium
The 1003 Mortgage Application plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.87. This is due the /inc/class/fnm/export.php file being publicly accessible with error logging enabled. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.
CVE-2024-51460 1 Ibm 1 Infosphere Information Server 2025-01-14 4.3 Medium
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system.
CVE-2024-39725 1 Ibm 2 Engineering Insights, Engineering Lifecycle Optimization - Engineering Insights 2025-01-10 5.3 Medium
IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
CVE-2023-33181 1 Xibosignage 1 Xibo 2025-01-09 4.3 Medium
Xibo is a content management system (CMS). Starting in version 3.0.0 and prior to version 3.3.5, some API routes will print a stack trace when called with missing or invalid parameters revealing sensitive information about the locations of paths that the server is using. Users should upgrade to version 3.3.5, which fixes this issue. There are no known workarounds aside from upgrading.
CVE-2023-34339 1 Jetbrains 1 Ktor 2025-01-08 3.3 Low
In JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's message
CVE-2023-23474 1 Ibm 1 Cognos Controller 2025-01-07 3.7 Low
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 245403.
CVE-2024-49818 1 Ibm 1 Security Guardium Key Lifecycle Manager 2025-01-07 4.3 Medium
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
CVE-2024-27315 1 Apache 1 Superset 2024-12-31 4.3 Medium
An authenticated user with privileges to create Alerts on Alerts & Reports has the capability to generate a specially crafted SQL statement that triggers an error on the database. This error is not properly handled by Apache Superset and may inadvertently surface in the error log of the Alert exposing possibly sensitive data. This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue.
CVE-2024-54366 2024-12-16 5.3 Medium
Generation of Error Message Containing Sensitive Information vulnerability in Dave Kiss Vimeography allows Retrieve Embedded Sensitive Data.This issue affects Vimeography: from n/a through 2.4.4.
CVE-2023-34110 1 Flask-appbuilder Project 1 Flask-appbuilder 2024-12-06 2.7 Low
Flask-AppBuilder is an application development framework, built on top of Flask. Prior to version 4.3.2, an authenticated malicious actor with Admin privileges, could by adding a special character on the add, edit User forms trigger a database error, this error is surfaced back to this actor on the UI. On certain database engines this error can include the entire user row including the pbkdf2:sha256 hashed password. This vulnerability has been fixed in version 4.3.2.
CVE-2023-37306 1 Misp-project 1 Malware Information Sharing Platform 2024-11-27 7.5 High
MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.
CVE-2023-43021 3 Ibm, Linux, Microsoft 4 Aix, Infosphere Information Server, Linux Kernel and 1 more 2024-11-21 5.3 Medium
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 266167.
CVE-2024-6984 1 Canonical 1 Juju 2024-11-21 8.8 High
An issue was discovered in Juju that resulted in the leak of the sensitive context ID, which allows a local unprivileged attacker to access other sensitive data or relation accessible to the local charm.
CVE-2024-5435 1 Gitlab 1 Gitlab 2024-11-21 4.5 Medium
An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 15.10 before 17.1.7, all versions starting from 17.2 before 17.2.5, all versions starting from 17.3 before 17.3.2 will disclose user password from repository mirror configuration.