Skip to main content

CWE archive

CWE-209 CVEs

Programmatic archive

574 CVEs tagged with CWE-20927 Critical, 74 High, 394 Medium, 78 Low, 1 Unrated.

CVE-2020-15125

Published Jul 29, 2020

In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the request object contained in the error object is used. The key for Auth…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4572

Published Jul 29, 2020

IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. Th…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13997

Published Jul 28, 2020

In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handling is enabled.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4319

Published Jul 28, 2020

IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 LTS, and 9.1 CD could allow under special circumstances, an authenticated user to obtain sensitive information due to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11252

Published Jul 23, 2020

The Kubernetes kube-controller-manager in versions v1.0-v1.17 is vulnerable to a credential leakage via error messages in mount failure logs and events for AzureFile and CephFS vo…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4341

Published Jun 24, 2020

IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4327

Published Jun 24, 2020

IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-6503

Published Jun 3, 2020

Inappropriate implementation in accessibility in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4357

Published May 27, 2020

IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This i…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-18865

Published May 7, 2020

Information disclosure via error message discrepancies in authentication functions in Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to enumerate va…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4085

Published Apr 22, 2020

"HCL Connections is vulnerable to possible information leakage and could disclose sensitive information via stack trace to a local user."

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4277

Published Apr 17, 2020

IBM TRIRIGA Application Platform 3.5.3 and 3.6.1 discloses sensitive information in error messages that could aid an attacker formulate future attacks. IBM X-Force ID: 175993.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4164

Published Apr 8, 2020

IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could expose sensitive information from applicatino errors which could be used in further attack…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-4601

Published Apr 8, 2020

IBM Quality Manager (RQM) 6.02, 6.06, and 6.0.6.1 could allow an authenticated user to obtain sensitive information from a stack trace that could aid in further attacks against th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11594

Published Apr 6, 2020

An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that causes a stack error to be shown providing the full fil…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4239

Published Mar 31, 2020

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 476-500 of 574 CVEsPage 20 of 23