Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or dis
Capgo before 12.128.2 contains improper error handling in the /private/accept_invitation endpoint that returns HTTP 500
Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Netty HTTP component. The ca
Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Undertow Component. The came
HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information
IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error messag
Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted con
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Ident
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that con
vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in
The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an aut
When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown
IBM Sterling B2B Integrator versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1, an
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.0, contains a generation o
Certain error messages returned by the application expose internal system details that should not be visible to end user
ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Success
HCL Traveler is affected by sensitive information disclosure. The application generates some error messages that provid
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability.
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information exposure vulnerability caused
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.
A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This imp
IBM Business Automation Workflow containers and traditional may leak information about its database structure in error m
HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an ar
HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, t
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow a remote attacker to obtain sensitive information w
SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with UPDATE ac
HCL BigFix Mobile is vulnerable to information disclosure due to improper handling of exceptions and verbose error repor
HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when i
A flaw was found in Keycloak. A remote attacker can exploit differential error messages during the identity-first login
The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRP
HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It inv
HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions
CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream respon
A vulnerability was found in wandb OpenUI up to 1.0/3.5-turb. Affected is the function generic_exception_handler of the
HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they ar
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is sensitive information disclosure in the
A generation of error message containing sensitive information vulnerability has been reported to affect HBS 3 Hybrid Ba
HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack tr
HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to
HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem str
In the web management interface of Archer AX72 (SG) v1, the network diagnostic feature improperly handles invalid user i
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.99, the POST /api/v1/admin/send
rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger p
Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.0, in non-debug mode Cryptomator m
HCL AION version 2 is affected by a Technical Error Disclosure vulnerability. This can expose sensitive technical detail
A Generation of Error Message Containing Sensitive Information vulnerability in the Materialized View Refresh mechanism
A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions before 8.6.85 contain a schema disclosure vulnerabilit
Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 8.2.2 before 8.6.87 disclose Pointer and Relation target cla
Frequently Asked Questions
What is CWE-209?
CWE-209 (CWE-209) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-209?
There are 697 CVE records associated with CWE-209 in our database. Of these, 27 are critical severity, 74 are high severity, and 394 are medium severity.
How can I protect against CWE-209 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-209 using AI-powered security agents.
Detect CWE-209 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-209 vulnerabilities across your infrastructure.
Get Started