CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

368 vulnerabilities with CWE-497
CVE-2023-37525 MEDIUM
HCL BigFix Compliance - Unauthenticated Sensitive Information Disclosure via WEB-INF Directory Access
CVSS 5.3
CVE-2023-23472 LOW
IBM InfoSphere DataStage Flow Designer - Info Disclosure
CVSS 3.1
CVE-2023-42010 LOW
IBM Sterling B2B Integrator <6.1.2.5, <6.2.0.2 - Info Disclosure
CVSS 3.1
CVE-2023-50180 MEDIUM
FortiADC <= 7.4.1, <= 7.2.3, <= 7.1.4, <= 7.0.5, < 6.2.6 - Exposure of Sensitive System Information
CVSS 5.5
CVE-2023-4605 MEDIUM
Lenovo XClarity Administrator - Info Disclosure
CVSS 6.5
CVE-2023-50959 MEDIUM
IBM Cloud Pak for Business Automation <23.0.2 - Info Disclosure
CVSS 5.3
CVE-2023-5081 LOW
Lenovo Tab M8 HD Firmware - Information Disclosure via Non-Resettable Device Identifier
CVSS 3.3
CVE-2023-41366 MEDIUM
SAP NetWeaver Application Server ABAP - Info Disclosure
CVSS 5.3
CVE-2023-34209 MEDIUM
EasyUse MailHunter Ultimate <2023 - Info Disclosure
CVSS 5.0
CVE-2023-4237 HIGH
Ansible Automation Platform - Info Disclosure
CVSS 7.3
CVE-2023-20111 MEDIUM
Cisco Identity Services Engine - Authenticated Exposure of Sensitive System Information via Web Management Interface
CVSS 6.5
CVE-2023-37487 MEDIUM
SAP Business One (Service Layer) - version 10.0 - Info Disclosure
CVSS 5.3
CVE-2023-0342 LOW
MongoDB Ops Manager <5.0.21, <6.0.12 - Info Disclosure
CVSS 3.1
CVE-2023-2541 MEDIUM
KNIME Business Hub <1.4.0 - Info Disclosure
CVSS 5.3
CVE-2023-32550 CRITICAL
Landscape < 19.10.5 - Sensitive Information Exposure via Server-Status Page
CVSS 9.3
CVE-2023-0005 MEDIUM
Palo Alto Networks PAN-OS - Info Disclosure
CVSS 4.1
CVE-2022-4985 HIGH
Vodafone H500s <3.5.10 - Info Disclosure
CVE-2022-50237 MEDIUM
ed25519-dalek < 2.0.0 - Private Key Exposure via Double Public Key Signing Oracle
CVSS 5.9
CVE-2022-43852 MEDIUM
IBM Aspera Console <3.4.4 - Info Disclosure
CVSS 5.3
CVE-2022-4968 MEDIUM
netplan < 1.0.1 - Exposure of Sensitive System Information via WireGuard Private Key Leak
CVSS 6.5
CVE-2022-34458 MEDIUM
Dell Command | Update <4.7 - Info Disclosure
CVSS 6.6
CVE-2022-38710 MEDIUM
IBM Robotic Process Automation <21.0.2 - Info Disclosure
CVSS 5.3
CVE-2022-2403 MEDIUM
OpenShift >=4.9 - Authenticated Credentials Leak via oauth-serving-cert ConfigMap
CVSS 6.5
CVE-2022-1902 HIGH
Red Hat Advanced Cluster Security - Privilege Escalation
CVSS 8.8
CVE-2022-20664 HIGH
Cisco Secure Email and Web Manager - Info Disclosure
CVSS 7.7
Details
Vulnerabilities 368