In JForum 2.1.8, an unauthenticated, remote attacker can enumerate whether a user exists by using the "create user" func
It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 generates an error message that includes sensitive informa
IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote attacker to obtain sensitive information, caused
parse-server before 3.6.0 allows account enumeration.
Leakage of stack traces in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch Io
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to obtain potentially sensitive stack traces by se
Seneca < 3.9.0 contains a vulnerability that could lead to exposing environment variables to unauthorized users.
An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x befor
Pydio 6.0.8 mishandles error reporting when a directory allows unauthenticated uploads, and the remote-upload option is
Server metadata could be exposed because one of the error messages reflected the whole response back to the client in Je
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote attacker to obtain sensitive infor
IBM Tivoli Netcool Impact 7.1.0 through 7.1.0.16 generates an error message that includes sensitive information about it
The Mijosoft MijoSearch component 2.0.1 and earlier for Joomla! allows remote attackers to obtain sensitive information
A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.4, when /websocket is requested and
_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 displays a message indicating whether an em
A full path disclosure vulnerability was discovered in Matomo v3.9.1 where a user can trigger a particular error to disc
IBM InfoSphere Information Server 11.5 and 11.7 is affected by an information disclosure vulnerability. Sensitive inform
Pydio Cells before 1.5.0, when supplied with a Name field in an unexpected Unicode format, fails to handle this and incl
IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 reveals sensitive information from a stack trace that could be used in f
IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analy
IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analy
IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analy
Class and method names in error message in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.
IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in
In affected versions of Sylius, exception messages from internal exceptions (like database exception) are wrapped by \Sy
A Username Enumeration via Error Message issue was discovered in NiceHash Miner before 2.0.3.0 because an "EMAIL DOES NO
In the Android kernel in the video driver there is a kernel pointer leak due to a WARN_ON statement. This could lead to
An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after e
Matera Banco 1.0.0 mishandles Java errors in the backend, as demonstrated by a stack trace revealing use of net.sf.acegi
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving err
Apache Ambari, version 2.5.0 to 2.6.2, passwords for Hadoop credential stores are exposed in Ambari Agent informational
In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evalu
In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerabilit
An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via
hawtio before versions 2.0-beta-1, 2.0-beta-2 2.0-m1, 2.0-m2, 2.0-m3, and 1.5 is vulnerable to a path traversal that lea
The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and inv
In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad q
The Web server in 3CX version 15.5.8801.3 is vulnerable to Information Leakage, because of improper error handling in St
A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to
Carestream Vue RIS, RIS Client Builds: Version 11.2 and prior running on a Windows 8.1 machine with IIS/7.5. When contac
The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, 7.1.x before 7.1.9,
389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout du
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a log pollution vulnerability potentiall
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user credentials, through a
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share.
Frequently Asked Questions
What is CWE-209?
CWE-209 (CWE-209) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-209?
There are 697 CVE records associated with CWE-209 in our database. Of these, 27 are critical severity, 74 are high severity, and 394 are medium severity.
How can I protect against CWE-209 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-209 using AI-powered security agents.
Detect CWE-209 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-209 vulnerabilities across your infrastructure.
Get Started