Vulnerabilities > Information Exposure Through an Error Message

DATE CVE VULNERABILITY TITLE RISK
2019-12-19 CVE-2019-19342 Information Exposure Through an Error Message vulnerability in Redhat Ansible Tower
A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.4, when /websocket is requested and the password contains the '#' character.
network
low complexity
redhat CWE-209
5.3
2019-12-11 CVE-2019-0404 Information Exposure Through an Error Message vulnerability in SAP Enable NOW 10/1902/1908
SAP Enable Now, before version 1911, leaks information about network configuration in the server error messages, leading to Information Disclosure.
network
low complexity
sap CWE-209
7.5
2019-12-05 CVE-2019-16768 Information Exposure Through an Error Message vulnerability in Sylius
In affected versions of Sylius, exception messages from internal exceptions (like database exception) are wrapped by \Symfony\Component\Security\Core\Exception\AuthenticationServiceException and propagated through the system to UI.
network
low complexity
sylius CWE-209
4.3
2019-11-25 CVE-2019-13697 Information Exposure Through an Error Message vulnerability in Google Chrome
Insufficient policy enforcement in performance APIs in Google Chrome prior to 77.0.3865.120 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
network
low complexity
google CWE-209
6.5
2019-11-22 CVE-2013-6879 Information Exposure Through an Error Message vulnerability in Miwisoft Mijosearch
The Mijosoft MijoSearch component 2.0.1 and earlier for Joomla! allows remote attackers to obtain sensitive information via a request to component/mijosearch/search, which reveals the installation path in an error message.
network
low complexity
miwisoft CWE-209
5.3
2019-11-22 CVE-2019-4570 Information Exposure Through an Error Message vulnerability in IBM Tivoli Netcool/Impact
IBM Tivoli Netcool Impact 7.1.0 through 7.1.0.16 generates an error message that includes sensitive information about its environment, users, or associated data.
network
low complexity
ibm CWE-209
5.3
2019-11-06 CVE-2019-6122 Information Exposure Through an Error Message vulnerability in Nicehash Miner
A Username Enumeration via Error Message issue was discovered in NiceHash Miner before 2.0.3.0 because an "EMAIL DOES NOT EXIST" error message occurs whenever a submitted email address is incorrect, but there is a different error message for invalid credentials with a correct email address.
network
high complexity
nicehash CWE-209
3.1
2019-10-09 CVE-2019-4512 Information Exposure Through an Error Message vulnerability in IBM products
IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in further attacks against the system.
network
low complexity
ibm CWE-209
4.3
2019-10-03 CVE-2019-4441 Information Exposure Through an Error Message vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser.
network
low complexity
ibm CWE-209
5.3
2019-10-02 CVE-2019-12156 Information Exposure Through an Error Message vulnerability in Jetbrains Upsource
Server metadata could be exposed because one of the error messages reflected the whole response back to the client in JetBrains TeamCity versions before 2018.2.5 and UpSource versions before 2018.2 build 1293.
network
low complexity
jetbrains CWE-209
5.3