The vulnerability exists within error.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. Syst
IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 could reveal sensitive information in HTTP 500 Internal Server Err
IBM Jazz Foundation products could allow an authenticated user to obtain sensitive information from a stack trace that c
Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a File and Directory Information Exposur
IBM API Connect 2018.1.0.0, 2018.2.1, 2018.2.2, 2018.2.3, and 2018.2.4 contains a vulnerability that could allow an auth
IBM Jazz Foundation products could disclose sensitive information to an authenticated attacker that could be used in fur
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. It was possible for the core_course_get_categori
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft
IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design
IBM Sterling B2B Integrator 5.2 through 5.2.6 could allow an authenticated attacker to obtain sensitive variable name in
IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote authenticated attacker to obtain sensitive informatio
A exposure of sensitive information vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Plugin.jav
It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying i
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 generates an error message that includes sensitiv
IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive information from the
HPE has identified a remote access to sensitive information vulnerability in HPE Network Function Virtualization Directo
IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 does not set the secure attribute on authorization token
The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access contro
A exposure of sensitive information vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in Computer.j
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to enumerate all user accounts
An information disclosure vulnerability in Fortinet FortiManager 6.0.1 and below versions allows a standard user with ad
foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize opt
foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a u
A flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReport
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in M
A vulnerability in BIG-IP APM portal access 11.5.1-11.5.7, 11.6.0-11.6.3, and 12.1.0-12.1.3 discloses the BIG-IP softwar
Tor Browser on Windows before 8.0 allows remote attackers to bypass the intended anonymity feature and discover a client
Lack of support for a non standard no-referrer policy value in Blink in Google Chrome prior to 64.0.3282.119 allowed a r
Citrix ShareFile StorageZones Controller before 5.4.2 has Information Exposure Through an Error Message.
A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authenticated, remote attacke
A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authenticated, remote attacke
IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 generates an error message that includes sensitive information about
Service workers can use redirection to avoid the tainting of cross-origin resources in some instances, allowing a malici
Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter key within a text i
Prayer through 1.3.5 sends a Referer header, containing a user's username, when a user clicks on a link in their email b
Information exposure vulnerability in SYNO.Core.ACL in Synology DiskStation Manager (DSM) before 6.2-23739-2 allows remo
IBM Jazz based applications (IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6, IBM
IBM Marketing Operations 9.1.0, 9.1.2, and 10.1 could allow a remote attacker to obtain sensitive information. An attack
The Report Builder of Jazz Reporting Service 5.0 through 5.0.2 and 6.0 through 6.0.6 could allow an authenticated user t
There is an information leak vulnerability in some Huawei smartphones. An attacker may do some specific configuration in
An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x befor
IBM Maximo Asset Management 7.6 could allow an authenticated user to enumerate usernames using a specially crafted HTTP
Dell Encryption (formerly Dell Data Protection | Encryption) v10.1.0 and earlier contain an information disclosure vulne
IBM Connections 5.0, 5.5, and 6.0 could allow an authenticated user to obtain sensitive information from invalid request
An information exposure vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in DirectoryBrowserSu
An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 generates an error message that in
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started