CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.
333 vulnerabilities with CWE-497
CVE-2024-39740
MEDIUM
IBM Datacap Navigator <9.1.10 - Info Disclosure
CVSS 4.3
CVE-2024-39675
HIGH
RUGGEDCOM <V4.3.10 - Path Traversal
CVSS 8.8
CVE-2024-31223
MEDIUM
Fides 2.19.0-2.39.2rc0 - Unauthenticated Exposure of Sensitive System Information via SERVER_SIDE_FIDES_API_URL
CVSS 5.3
CVE-2024-5735
HIGH
AdmirorFrames <5.0 - Info Disclosure
CVSS 7.5
CVE-2024-6388
MEDIUM
Ubuntu Advantage Desktop Daemon <1.12 - Info Disclosure
CVSS 5.9
CVE-2024-4008
CRITICAL
ABB FTS Display and BCU - KNX Bus Control via FDSK Leak
CVSS 9.6
CVE-2024-36070
HIGH
tine < 2023.11.8 - Unauthenticated Sensitive Information Exposure via Setup.php
CVSS 7.5
CVE-2024-1809
MEDIUM
Analytify < 5.2.3 - Authenticated Sensitive Information Exposure via AJAX
CVSS 5.4
CVE-2024-31887
HIGH
IBM Security Verify Privilege <11.6.25 - Info Disclosure
CVSS 7.5
CVE-2024-3774
MEDIUM
aEnrich a+HRD - Unauthenticated Sensitive Information Exposure via System Configuration Parameter
CVSS 5.3
CVE-2024-31419
MEDIUM
OpenShift Virtualization - Info Disclosure
CVSS 4.3
CVE-2024-0053
LOW
Android - Local Information Disclosure via PrintManagerService getCustomPrinterIcon
CVSS 3.3
CVE-2024-25634
HIGH
alf.io <2.0-Mr-2402 - Info Disclosure
CVSS 7.2
CVE-2024-22125
HIGH
Microsoft Edge <1.0 - Info Disclosure
CVSS 7.4
CVE-2024-22124
MEDIUM
SAP NetWeaver ICM and Web Dispatcher - Exposure of Sensitive System Information
CVSS 4.1
CVE-2023-37525
MEDIUM
HCL BigFix Compliance - Unauthenticated Sensitive Information Disclosure via WEB-INF Directory Access
CVSS 5.3
CVE-2023-23472
LOW
IBM InfoSphere DataStage Flow Designer - Info Disclosure
CVSS 3.1
CVE-2023-42010
LOW
IBM Sterling B2B Integrator <6.1.2.5, <6.2.0.2 - Info Disclosure
CVSS 3.1
CVE-2023-50180
MEDIUM
FortiADC <= 7.4.1, <= 7.2.3, <= 7.1.4, <= 7.0.5, < 6.2.6 - Exposure of Sensitive System Information
CVSS 5.5
CVE-2023-4605
MEDIUM
Lenovo XClarity Administrator - Info Disclosure
CVSS 6.5
CVE-2023-50959
MEDIUM
IBM Cloud Pak for Business Automation <23.0.2 - Info Disclosure
CVSS 5.3
CVE-2023-5081
LOW
Lenovo Tab M8 HD Firmware - Information Disclosure via Non-Resettable Device Identifier
CVSS 3.3
CVE-2023-41366
MEDIUM
SAP NetWeaver Application Server ABAP - Info Disclosure
CVSS 5.3
CVE-2023-34209
MEDIUM
EasyUse MailHunter Ultimate <2023 - Info Disclosure
CVSS 5.0
CVE-2023-4237
HIGH
Ansible Automation Platform - Info Disclosure
CVSS 7.3
Details
Vulnerabilities
333