Vulnerabilities > Information Exposure Through an Error Message
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-09-15 | CVE-2020-24925 | Information Exposure Through an Error Message vulnerability in Elkarbackup 1.3.3 A Sensitive Source Code Path Disclosure vulnerability is found in ElkarBackup v1.3.3. | 7.5 |
2020-09-11 | CVE-2018-19947 | Information Exposure Through an Error Message vulnerability in Qnap Helpdesk The vulnerability have been reported to affect earlier versions of Helpdesk. | 6.5 |
2020-08-27 | CVE-2020-4166 | Information Exposure Through an Error Message vulnerability in IBM Security Guardium Insights 2.0.1 IBM Security Guardium Insights 2.0.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. | 5.3 |
2020-08-26 | CVE-2019-4699 | Information Exposure Through an Error Message vulnerability in IBM products IBM Security Guardium Data Encryption (GDE) 3.0.0.2 generates an error message that includes sensitive information about its environment, users, or associated data. | 2.7 |
2020-08-05 | CVE-2020-15132 | Information Exposure Through an Error Message vulnerability in Sulu In Sulu before versions 1.6.35, 2.0.10, and 2.1.1, when the "Forget password" feature on the login screen is used, Sulu asks the user for a username or email address. | 5.3 |
2020-07-31 | CVE-2020-14337 | Information Exposure Through an Error Message vulnerability in Redhat Ansible Tower 3.0.0 A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes. | 5.8 |
2020-07-30 | CVE-2020-8213 | Information Exposure Through an Error Message vulnerability in UI Unifi Protect 1.13.3 An information exposure vulnerability exists in UniFi Protect before v1.13.4-beta.5 that allowed unauthenticated attackers access to valid usernames for the UniFi Protect web application via HTTP response code and response timing. | 5.3 |
2020-07-29 | CVE-2020-15125 | Information Exposure Through an Error Message vulnerability in Auth0 Auth0.Js In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the request object contained in the error object is used. | 7.7 |
2020-07-29 | CVE-2020-4572 | Information Exposure Through an Error Message vulnerability in IBM Security KEY Lifecycle Manager 3.0.1/4.0 IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. | 5.3 |
2020-07-28 | CVE-2020-13997 | Information Exposure Through an Error Message vulnerability in Shopware In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handling is enabled. | 7.5 |