CWE-598

Use of HTTP Request With Sensitive Query String

Parent: CWE-201 - Insertion of Sensitive Information Into Sent Data

The web application uses an HTTP method to process a request, but the request includes sensitive information in the query string.

87 vulnerabilities with CWE-598
CVE-2022-22551 HIGH
DELL EMC AppSync <4.3 - Info Disclosure
CVSS 8.3
CVE-2021-41719 HIGH
Mahavitran IOS App <16.1 - Info Disclosure
CVSS 7.5
CVE-2021-36328 HIGH
Dell EMC Streaming Data Platform <1.3 - SQL Injection
CVSS 8.8
CVE-2021-21594 HIGH
Dell PowerScale OneFS <9.1.0.x - Info Disclosure
CVSS 8.2
CVE-2020-5331 HIGH
RSA Archer < 6.7.0.3 - Authenticated Exposure of Sensitive Information in Log Files
CVSS 8.8
CVE-2019-18573 HIGH
RSA Identity Governance <7.1.1 P03 - Session Fixation
CVSS 8.8
CVE-2019-6531 HIGH
Kunbus PR100088 <R02-1.1.13166 - Info Disclosure
CVSS 8.1
CVE-2018-14822 CRITICAL
Entes EMG12 <2.57 - Info Disclosure
CVSS 9.8
CVE-2018-5467 MEDIUM
Belden Hirschmann - Info Disclosure
CVSS 6.5
CVE-2017-9280 MEDIUM
NetIQ Identity Manager <4.5.6.1 - Info Disclosure
CVSS 4.3
CVE-2017-3185 CRITICAL
ACTi D, B, I, and E series cameras >=A1D-500-V6.11.31-AC - Exposure of Sensitive Information via GET Requests
CVSS 9.8
CVE-2017-8443 MEDIUM
Kibana X-Pack Security < 5.4.3 - Unauthenticated Credential Exposure via Crafted Login URL
CVSS 6.5
Details
Vulnerabilities 87