Mailform Pro CGI prior to 4.3.4 generates error messages containing sensitive information, which may allow a remote unau
IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain sensitive information when a de
OMERO.web provides a web based client and plugin infrastructure. Prior to version 5.29.2, if an error occurred when rese
HCL BigFix SaaS Authentication Service is affected by a sensitive information disclosure. Under certain conditions, err
Information disclosure vulnerability in error handling in MiR software prior to version 3.0.0 allows unauthenticated att
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024
Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remo
The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially
Error Messages Wrapped In HTTP Header.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Prior to September 19, 2025, the Hospital Manager Backend Services returned verbose ASP.NET error pages for invalid WebR
Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, includi
In writeContent of RemotePrintDocument.java, there is a possible information disclosure due to a logic error. This could
There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages
Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in
An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting f
IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could allow a remote attacker to obtain sensitive information when a detaile
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive
IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed technic
IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message i
HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal
Generation of Error Message Containing Sensitive Information vulnerability in vcita Online Booking & Scheduling Calendar
IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical erro
IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error
IBM Verify Identity Access Digital Credentials 24.06 could allow a remote attacker to obtain sensitive information when
IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain information about the applicati
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a
A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/u
Error messages containing sensitive information in the File Abstraction Layer in TYPO3 CMS versions 9.0.0-9.5.54, 10.0.0
Directus is a real-time API and App dashboard for managing SQL database content. An observable difference in error messa
A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows
Debug information disclosure in the SQL error message to in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes
IBM Planning Analytics Local 2.1.0 - 2.1.15 could disclose sensitive information about server architecture that could ai
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.4.6, 18.5 before 18.5.4, and 1
Due to improper error handling in SAP Business Objects Business Intelligence Platform, technical details of the applicat
Jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Pr
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive
A vulnerability was found in atjiu pybbs up to 6.0.0 and classified as problematic. This issue affects the function send
A vulnerability was determined in mtons mblog up to 3.5.0. Affected is an unknown function of the file /register. The ma
The SolarWinds Platform is vulnerable to an information disclosure vulnerability through an error message. While the dat
When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error
A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Au
HCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes sensitive information.
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret
Frequently Asked Questions
What is CWE-209?
CWE-209 (CWE-209) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-209?
There are 697 CVE records associated with CWE-209 in our database. Of these, 27 are critical severity, 74 are high severity, and 394 are medium severity.
How can I protect against CWE-209 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-209 using AI-powered security agents.
Detect CWE-209 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-209 vulnerabilities across your infrastructure.
Get Started