CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

368 vulnerabilities with CWE-497
CVE-2024-36509 MEDIUM
FortiWeb 6.3.0-6.3.23, 7.0.0-7.0.10, 7.2.0-7.2.10, 7.4.0-7.4.3, 7.6.0 - Sensitive Info Exposure via Log Access
CVSS 4.2
CVE-2024-47799 LOW
Mesh Wi-Fi router RP562B <v1.0.2 - Info Disclosure
CVSS 3.5
CVE-2024-50528 HIGH
Stacks Mobile App Builder <5.2.3 - Info Disclosure
CVSS 7.5
CVE-2024-50425 MEDIUM
WP Booking System <= 2.0.19.10 - Exposure of Sensitive System Information
CVSS 6.5
CVE-2024-48024 HIGH
Fahad Mahmood Keep Backup Daily <2.0.7 - Info Disclosure
CVSS 7.5
CVE-2024-49252 MEDIUM
Leyka <= 3.31.6 - Exposure of Sensitive System Information
CVSS 5.3
CVE-2024-9470 MEDIUM
Cortex XSOAR 6.12.0-6.12.0 (Build 1271551), 6.13.0+, 8.0.0+ - Unauthorized Incident Data Exposure
CVE-2024-6389 MEDIUM
GitLab-CE/EE <17.1.7, <17.2.5, <17.3.2 - Info Disclosure
CVSS 4.3
CVE-2024-8687 HIGH
Palo Alto Networks PAN-OS - Info Disclosure
CVSS 7.1
CVE-2024-39740 MEDIUM
IBM Datacap Navigator <9.1.10 - Info Disclosure
CVSS 4.3
CVE-2024-39675 HIGH
RUGGEDCOM <V4.3.10 - Path Traversal
CVSS 8.8
CVE-2024-31223 MEDIUM
Fides 2.19.0-2.39.2rc0 - Unauthenticated Exposure of Sensitive System Information via SERVER_SIDE_FIDES_API_URL
CVSS 5.3
CVE-2024-5735 HIGH
AdmirorFrames <5.0 - Info Disclosure
CVSS 7.5
CVE-2024-6388 MEDIUM
Ubuntu Advantage Desktop Daemon <1.12 - Info Disclosure
CVSS 5.9
CVE-2024-4008 CRITICAL
ABB FTS Display and BCU - KNX Bus Control via FDSK Leak
CVSS 9.6
CVE-2024-36070 HIGH
tine < 2023.11.8 - Unauthenticated Sensitive Information Exposure via Setup.php
CVSS 7.5
CVE-2024-1809 MEDIUM
Analytify < 5.2.3 - Authenticated Sensitive Information Exposure via AJAX
CVSS 5.4
CVE-2024-31887 HIGH
IBM Security Verify Privilege <11.6.25 - Info Disclosure
CVSS 7.5
CVE-2024-3774 MEDIUM
aEnrich a+HRD - Unauthenticated Sensitive Information Exposure via System Configuration Parameter
CVSS 5.3
CVE-2024-31419 MEDIUM
OpenShift Virtualization - Info Disclosure
CVSS 4.3
CVE-2024-0053 LOW
Android - Local Information Disclosure via PrintManagerService getCustomPrinterIcon
CVSS 3.3
CVE-2024-25634 HIGH
alf.io <2.0-Mr-2402 - Info Disclosure
CVSS 7.2
CVE-2024-22125 HIGH
Microsoft Edge <1.0 - Info Disclosure
CVSS 7.4
CVE-2024-22124 MEDIUM
SAP NetWeaver ICM and Web Dispatcher - Exposure of Sensitive System Information
CVSS 4.1
CVE-2023-37507 HIGH
An information disclosure vulnerability affects HCL DevOps Plan
CVSS 7.5
Details
Vulnerabilities 368