IBM WebSphere Application Server Proxy Server or On-demand-router (ODR) 7.0, 8.0, 8.5, 9.0 and could allow a local attac
IBM MaaS360 DTM all versions up to 3.81 does not perform proper verification for user rights of certain applications whi
IBM Sametime Connect 8.5.2 and 9.0, after uninstalling the Sametime Rich Client, could disclose potentially sensitive in
IBM Sametime 8.5.2 and 9.0 could store potentially sensitive information from the browser cache locally that could be av
The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1;
selinux-policy as packaged in Red Hat OpenShift 2 allows attackers to obtain process listing information via a privilege
Skybox Manager Client Application is prone to information disclosure via a username enumeration attack. A local unauthen
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "Directory Uti
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Location Framework
Jenkins Git Client Plugin 2.4.2 and earlier creates temporary file with insecure permissions resulting in information di
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Dictionary
An issue was discovered in certain Apple products. iOS before 11.1 is affected. macOS before 10.13.1 is affected. tvOS b
In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p4, 11.0-RELEASE-p15, 10.4-STABLE, 10.4-RELEASE-p3, and 10.3-RELEASE-p24, no
In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p4, 11.0-RELEASE-p15, 10.4-STABLE, 10.4-RELEASE-p3, and 10.3-RELEASE-p24, th
Prior to 4.4.1.10, the Norton Family Android App can be susceptible to an Information Disclosure issue. Information disc
IBM Security Guardium 10.0 stores potentially sensitive information in log files that could be read by a local user. IBM
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 mishandles states_equal comparisons between the pointer data ty
An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent to the serve
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: X Plugin). Supported versions that ar
Windows Media Player in Microsoft Windows 8.1; Windows Server 2012 R2; Windows RT 8.1; Windows 7 SP1; Windows 2008 SP2 a
An unspecified vulnerability in IBM Rhapsody DM 4.0, 5.0, and 6.0 could allow an attacker to perform a JSON Hijacking At
Cloudera Navigator 2.2.x before 2.2.4 and 2.3.x before 2.3.3 include support for SSLv3 when configured to use SSL/TLS, w
NetIQ Access Manager 4.2 before SP3 HF1 and 4.3 before SP1 HF1, when configured as a SAML 2.0 Identity Server with Virtu
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp i
The Datadog Plugin stores an API key to access the Datadog service in the global Jenkins configuration. While the API ke
ChakraCore and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 170
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local attacker to obtain sensitive information using HTTP He
IBM Security Access Manager for Web could allow an authenticated attacker to obtain sensitive information from error mes
Vulnerability in the Oracle Integrated Lights Out Manager (ILOM) component of Oracle Sun Systems Products Suite (subcomp
Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012
Cybozu KUNAI for Android 3.0.4 to 3.0.5.1 allow remote attackers to obtain log information through a malicious Android a
IBM Business Process Manager 7.5, 8.0, and 8.5 temporarily stores files in a temporary folder during offline installs wh
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could disclose sensitive information to a local use
Windows Media Player in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 a
Microsoft Graphics Component in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, a
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Media Player" co
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Accessibility" c
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Clipboard" compo
An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "Accounts" compon
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. The issue involves the "Notifications"
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "Screen Lock"
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Phone" component.
An issue was discovered in certain Apple products. iOS before 11.1 is affected. The issue involves the "Siri" component.
An issue was discovered in certain Apple products. iOS before 11.1 is affected. The issue involves the "Messages" compon
The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit the
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started