IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical err
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, when a download error i
If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported
An issue was identified in GitLab EE 13.4 or later which leaked internal IP address via error messages.
An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UP
IBM OpenPages GRC Platform 8.1 could allow a remote attacker to obtain sensitive information when a detailed technical e
A vulnerability has been identified in Mendix Excel Importer Module (All versions < V9.0.3). Uploading a manipulated XML
Uploading a table mapping using a manipulated XML file results in an exception that could expose information about the a
IBM Guardium Data Encryption (GDE) 4.0.0.4 could allow a remote attacker to obtain sensitive information when a detailed
IBM Guardium Data Encryption (GDE) 4.0.0.4 could allow a remote attacker to obtain sensitive information when a detailed
IBM Cloud Pak for Applications 4.3 could allow a remote attacker to obtain sensitive information when a detailed technic
IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2 could allow a remote attacker to obtain sensitive information when a detailed tec
A verbose error message in GitLab EE affecting all versions since 12.2 could disclose the private email address of a use
IBM Security Secret Server up to 11.0 could allow a remote attacker to obtain sensitive information when a detailed tech
IBM Edge 4.2 could reveal sensitive version information about the server from error pages that could aid an attacker in
IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 could allow a remote attacker to obtain sensitive information when a d
IBM Sterling File Gateway 6.0.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a d
A vulnerability in the web-based dashboard of Cisco Umbrella could allow an authenticated, remote attacker to perform an
django-registration is a user registration package for Django. The django-registration package provides tools for implem
Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to information dis
An issue has been discovered in GitLab affecting all versions starting with 7.1. A member of a private group was able to
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, the
IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a remote attacker to obtain sensitive information when
A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.
IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed t
IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed t
IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information when a detailed technical error
In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the request obj
An issue was discovered in GitLab Community and Enterprise Edition 8.3 through 11.11. It allows Information Exposure thr
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request t
IBM TRIRIGA Application Platform 3.5.3 and 3.6.1 discloses sensitive information in error messages that could aid an att
The Journal theme before 3.1.0 for OpenCart allows exposure of sensitive data via SQL errors.
In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and v
A Sensitive Source Code Path Disclosure vulnerability is found in ElkarBackup v1.3.3. An attacker is able to view the pa
IBM i2 iBase 8.9.13 could allow a remote attacker to obtain sensitive information when a detailed technical error messag
"HCL Connections is vulnerable to possible information leakage and could disclose sensitive information via stack trace
Inappropriate implementation in accessibility in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtai
Information leak in content security policy in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cro
When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was
Trend Micro Antivirus for Mac 2020 (Consumer) has a vulnerability in a specific kernel extension where an attacker could
The Kubernetes kube-controller-manager in versions v1.0-v1.17 is vulnerable to a credential leakage via error messages i
A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes. This flaw a
IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive
SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper
Evoko Home 1.31 devices provide different error messages for failed login requests depending on whether the username is
Certain settings page(s) in SAP Business Objects Business Intelligence Platform (CMC), version 4.2, generates error mess
An issue was discovered in SmartClient 12.0. If an unauthenticated attacker makes a POST request to /tools/developerCons
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Several full path disclosure vulnera
An issue was discovered in Zammad 3.0 through 3.2. It may respond with verbose error messages that disclose internal app
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 could allow a remote attacker to obtain sensitive information when a
Frequently Asked Questions
What is CWE-209?
CWE-209 (CWE-209) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-209?
There are 697 CVE records associated with CWE-209 in our database. Of these, 27 are critical severity, 74 are high severity, and 394 are medium severity.
How can I protect against CWE-209 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-209 using AI-powered security agents.
Detect CWE-209 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-209 vulnerabilities across your infrastructure.
Get Started