A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive i
The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated users to discover all subscriber e
Pulse Secure Virtual Traffic Manager 9.9 versions prior to 9.9r2 and 10.4r1 allow a remote authenticated user to obtain
In XBLRamDump mode, there is a debug feature that can be used to dump memory contents, if an attacker has physical acces
An information disclosure vulnerability exists when the browser scripting engine improperly handle object types, aka "Mi
A vulnerability in the UPC bar code of the Avanti Markets MarketCard could allow an unauthenticated, local attacker to a
The installation process in IBM Security Key Lifecycle Manager 2.5 stores unencrypted credentials, which might allow loc
An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14,
The Identity and Access Management (IAM) services (IBM Cloud Private 3.1.0) do not use a secure channel, such as SSL, to
IBM Spectrum Scale 4.1.1 and 4.2.0 - 4.2.3 could allow a local unprivileged user access to information located in dump f
IBM Business Process Manager 8.6 allows web pages to be stored locally which can be read by another user on the system.
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains a vulnerability in the rmsock command that may be used to expose kernel memory.
Open Whisper Signal (aka Signal-Desktop) before 1.15.0-beta.10 allows information leakage.
IBM QRadar SIEM 7.2 and 7.3 allows web pages to be stored locally which can be read by another user on the system. IBM X
IBM i2 Enterprise Insight Analysis 2.1.7 allows web pages to be stored locally which can be read by another user on the
IBM WebSphere Application Server 9 could allow sensitive information to be available caused by mishandling of data by th
The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information.
The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, whic
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 stores sensitive information in URL parameters. This may lead to info
When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as
A Password in Configuration File issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, V
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 does not set the secure flag for the
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 might allow remote attackers to obta
In Apache Hive 0.6.0 to 2.3.2, malicious user might use any xpath UDFs (xpath/xpath_string/xpath_boolean/xpath_number/xp
An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 stores sensitive information in URL parameters. This may lead t
An exploitable file write vulnerability exists in the memory module functionality of Allen Bradley Micrologix 1400 Serie
An undisclosed vulnerability in Jazz common products exists with potential for information disclosure. IBM X-Force ID: 1
IBM Security Identity Governance and Intelligence Virtual Appliance 5.2 through 5.2.3.2 stores sensitive information in
The iTrack device tracking ID number, also called "LosserID" in the web API, can be obtained by being in the range of an
jenkins-mailer-plugin before version 1.20 is vulnerable to an information disclosure while using the feature to send ema
jenkins-email-ext before version 2.57.1 is vulnerable to an Information Exposure. The Email Extension Plugins is able to
Carestream Vue RIS, RIS Client Builds: Version 11.2 and prior running on a Windows 8.1 machine with IIS/7.5. When contac
Caddy through 0.11.0 sends incorrect certificates for certain invalid requests, making it easier for attackers to enumer
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 stores sensitive information in URL parameters. This may
IBM Security Guardium 10.0 and 10.5 stores sensitive information in URL parameters. This may lead to information disclos
NFC (Near Field Communication) module in Huawei mobile phones with software LON-AL00BC00 has an information leak vulnera
The Trackr device ID is constructed of a manufacturer identifier of four zeroes followed by the BLE MAC address in rever
An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discover
Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains an Information Exposure vulnerability. The log f
IBM Security Access Manager Appliance 9.0.0 allows web pages to be stored locally which can be read by another user on t
IBM WebSphere Application Server (IBM Liberty for Java for Bluemix 3.15) could allow a local attacker to obtain sensitiv
A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an unauthenticated, local
A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could all
A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could all
IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial
The ProcessVolumeDeviceControlIrp function in Ntdriver.c in TrueCrypt 7.1a allows local users to bypass access restricti
IBM Rational Collaborative Lifecycle Management (CLM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before
The Administration and Reporting tool in IBM Rational License Key Server (RLKS) before 8.1.4.9 iFix 04 allows local user
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Sandbox Profiles"
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started