PgHero before 3.1.0 allows Information Disclosure via EXPLAIN because query results may be present in an error message.
Generation of Error Message Containing Sensitive Information vulnerability in the Apache Airflow AWS Provider. This iss
No exception handling vulnerability which revealed sensitive or excessive information to users.
MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive informati
Server information leak of configuration data when an error is generated in response to a specially crafted message. See
CodeIgniter is a PHP full-stack web framework. Prior to CodeIgniter4 version 4.4.3, if an error or exception occurs, a d
ReadtoMyShoe, a web app that lets users upload articles and listen to them later, generates an error message containing
Saleor is a headless, GraphQL commerce platform delivering personalized shopping experiences. Some internal Python excep
IBM MQ 8.0, 9.0, and 9.1 could allow a local user to obtain sensitive credential information when a detailed technical e
In registerPhoneAccount of PhoneAccountRegistrar.java, uncaught exceptions in parsing persisted user data could lead to
An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access s
Brocade Fabric OS before Brocade Fabric OS 9.1.1c, 9.2.0 contains a vulnerability when using various commands such as “c
Grafana is an open-source platform for monitoring and observability. The Google Sheets data source plugin for Grafana,
Alotcer - AR7088H-A firmware version 16.10.3 Information disclosure. Unspecified error message contains the default admi
Wyse Management Suite Repository 3.8 and below contain an information disclosure vulnerability. A unauthenticated attac
SonicWall Email Security contains a vulnerability that could permit a remote unauthenticated attacker access to an error
Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.
An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When a password reset request occurs, the serv
IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could disclose sensitive information in an error message. This informat
In affected versions of Octopus Deploy it is possible to discover network details via error message
An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 all
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a remote attacker to obtain system information without authe
e-Excellence U-Office Force generates an error message in webiste service. An unauthenticated remote attacker can obtai
IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) could allow a remote attacker to o
Due to the lack of validation, SAP BusinessObjects Business Intelligence Platform (Version Management System) - version
The response messages received from the eSOMS report generation using certain parameter queries with full file path can
The Pimcore Admin Classic Bundle provides a Backend UI for Pimcore. Full Path Disclosure (FPD) vulnerabilities enable th
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed te
The OPC UA .NET Standard Reference Server before 1.4.371.86. places sensitive information into an error message that may
Due to improper error handling, a REST API resource could expose a server side error containing an internal WSO2 specifi
IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 could allow a remote attac
IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to obtain sensitive information when a det
ONTAP Mediator versions prior to 1.7 are susceptible to a vulnerability that can allow an unauthenticated attacker to e
A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.7 could allow a remote attac
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to obtain
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the ta
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the fu
Xibo is a content management system (CMS). Starting in version 3.0.0 and prior to version 3.3.5, some API routes will pr
IBM TRIRIGA 3.0, 4.0, and 4.4 could allow a remote attacker to obtain sensitive information when a detailed technical er
IBM Security Verify Information Queue 10.0.4 and 10.0.5 could allow a remote attacker to obtain sensitive information th
IBM Security Verify Information Queue 10.0.4 and 10.0.5 could allow a remote attacker to obtain sensitive information th
By default, stack traces for errors were enabled, which resulted in the exposure of internal traces on REST API endpoint
The Statutory Reporting application has a vulnerable file storage location, potentially enabling low privileged attacker
IBM System Storage Virtualization Engine TS7700 3957-VEC, 3948-VED and 3957-VEC could allow a remote attacker to obtain
Kaifa Technology WebITR is an online attendance system. A remote attacker with regular user privilege can obtain partial
HCL Launch could allow a remote attacker to obtain sensitive information when a detailed technical error message is retu
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application returns inconsis
Saleor is a headless, GraphQL commerce platform delivering personalized shopping experiences. Some internal Python excep
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in sumocoders FrameworkUserBundle up to 1.3.x. It has been rat
Frequently Asked Questions
What is CWE-209?
CWE-209 (CWE-209) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-209?
There are 697 CVE records associated with CWE-209 in our database. Of these, 27 are critical severity, 74 are high severity, and 394 are medium severity.
How can I protect against CWE-209 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-209 using AI-powered security agents.
Detect CWE-209 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-209 vulnerabilities across your infrastructure.
Get Started