CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

311 vulnerabilities with CWE-497
CVE-2024-49252 MEDIUM
Leyka <3.31.6 - Info Disclosure
CVSS 5.3
CVE-2024-9470 MEDIUM
Cortex XSOAR - Info Disclosure
CVE-2024-6389 MEDIUM
GitLab-CE/EE <17.1.7, <17.2.5, <17.3.2 - Info Disclosure
CVSS 4.3
CVE-2024-8687 HIGH
Palo Alto Networks PAN-OS - Info Disclosure
CVSS 7.1
CVE-2024-39740 MEDIUM
IBM Datacap Navigator <9.1.10 - Info Disclosure
CVSS 4.3
CVE-2024-39675 HIGH
RUGGEDCOM <V4.3.10 - Path Traversal
CVSS 8.8
CVE-2024-31223 MEDIUM
Fides <2.39.2rc0 - Info Disclosure
CVSS 5.3
CVE-2024-5735 HIGH
AdmirorFrames <5.0 - Info Disclosure
CVSS 7.5
CVE-2024-6388 MEDIUM
Ubuntu Advantage Desktop Daemon <1.12 - Info Disclosure
CVSS 5.9
CVE-2024-4008 CRITICAL
ABB, Busch-Jaeger, FTS Display <1.00 & BCU <1.3.0.33 - RCE
CVSS 9.6
CVE-2024-36070 HIGH
tine <2023.11.8 - Info Disclosure
CVSS 7.5
CVE-2024-1809 MEDIUM
Analytify - Google Analytics Dashboard < 5.2.4 - Missing Authorization
CVSS 5.4
CVE-2024-31887 HIGH
IBM Security Verify Privilege <11.6.25 - Info Disclosure
CVSS 7.5
CVE-2024-3774 MEDIUM
Aenrich A+hrd - Missing Authentication
CVSS 5.3
CVE-2024-31419 MEDIUM
OpenShift Virtualization - Info Disclosure
CVSS 4.3
CVE-2024-0053 LOW
Google Android - Information Disclosure
CVSS 3.3
CVE-2024-25634 HIGH
alf.io <2.0-Mr-2402 - Info Disclosure
CVSS 7.2
CVE-2024-22125 HIGH
Microsoft Edge <1.0 - Info Disclosure
CVSS 7.4
CVE-2024-22124 MEDIUM
SAP - Info Disclosure
CVSS 4.1
CVE-2023-37525 MEDIUM
Hcltech Bigfix Compliance - Information Disclosure
CVSS 5.3
CVE-2023-23472 LOW
IBM InfoSphere DataStage Flow Designer - Info Disclosure
CVSS 3.1
CVE-2023-42010 LOW
IBM Sterling B2B Integrator <6.1.2.5, <6.2.0.2 - Info Disclosure
CVSS 3.1
CVE-2023-50180 MEDIUM
FortiADC <7.4.1 - Info Disclosure
CVSS 5.5
CVE-2023-4605 MEDIUM
Lenovo XClarity Administrator - Info Disclosure
CVSS 6.5
CVE-2023-50959 MEDIUM
IBM Cloud Pak for Business Automation <23.0.2 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 311