CWE-598

Use of HTTP Request With Sensitive Query String

Parent: CWE-201 - Insertion of Sensitive Information Into Sent Data

The web application uses an HTTP method to process a request, but the request includes sensitive information in the query string.

74 vulnerabilities with CWE-598
CVE-2023-50954 MEDIUM
IBM InfoSphere Information Server 11.7 - Info Disclosure
CVSS 4.3
CVE-2023-32335 LOW
IBM Maximo Application Suite - Information Disclosure
CVSS 3.7
CVE-2023-45716 LOW
Sametime - Info Disclosure
CVSS 1.7
CVE-2023-50328 LOW
IBM PowerSC <2.2 - Info Disclosure
CVSS 3.7
CVE-2023-6287 LOW
Tribe29 Checkmk Appliance <1.6.8 - Info Disclosure
CVSS 3.3
CVE-2023-6014 CRITICAL
MLflow < 2.8.0 - Authentication Bypass
CVSS 9.8
CVE-2023-37935 MEDIUM
Fortinet FortiOS <7.0.12-7.2.5-7.4.0 - Info Disclosure
CVSS 6.5
CVE-2023-25524 MEDIUM
Nvidia Omniverse Launcher < 1.8.11 - Information Disclosure
CVSS 4.0
CVE-2023-22307 MEDIUM
Tribe29 Checkmk Appliance <1.6.4 - Info Disclosure
CVSS 5.5
CVE-2022-34452 LOW
Dell Powerpath Management Appliance < 3.4 - Information Disclosure
CVSS 2.7
CVE-2022-24414 HIGH
Dell EMC CloudLink <7.1.3 - Info Disclosure
CVSS 7.6
CVE-2022-25787 HIGH
Secomea Gatemanager 4250 Firmware - Information Disclosure
CVSS 7.5
CVE-2022-22551 HIGH
DELL EMC AppSync <4.3 - Info Disclosure
CVSS 8.3
CVE-2021-41719 HIGH
Mahavitran IOS App <16.1 - Info Disclosure
CVSS 7.5
CVE-2021-36328 HIGH
Dell EMC Streaming Data Platform <1.3 - SQL Injection
CVSS 8.8
CVE-2021-21594 HIGH
Dell PowerScale OneFS <9.1.0.x - Info Disclosure
CVSS 8.2
CVE-2020-5331 HIGH
RSA Archer < 6.7.0.3 - Information Disclosure
CVSS 8.8
CVE-2019-18573 HIGH
RSA Identity Governance <7.1.1 P03 - Session Fixation
CVSS 8.8
CVE-2019-6531 HIGH
Kunbus PR100088 <R02-1.1.13166 - Info Disclosure
CVSS 8.1
CVE-2018-14822 CRITICAL
Entes EMG12 <2.57 - Info Disclosure
CVSS 9.8
CVE-2018-5467 MEDIUM
Belden Hirschmann - Info Disclosure
CVSS 6.5
CVE-2017-9280 MEDIUM
NetIQ Identity Manager <4.5.6.1 - Info Disclosure
CVSS 4.3
CVE-2017-3185 CRITICAL
Acti Camera Firmware - Information Disclosure
CVSS 9.8
CVE-2017-8443 MEDIUM
Elastic Kibana < 5.4.2 - Information Disclosure
CVSS 6.5
Details
Vulnerabilities 74