In affected versions of Octopus Deploy it is possible to reveal the Space ID of spaces that the user does not have acces
Hitachi Energy LinkOne product, has a vulnerability due to a web server misconfiguration, that enables debug mode and re
Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud, similar to Trello. The full path of t
Generation of Error Message Containing Sensitive Information vulnerability in Hitachi JP1/Automatic Operation allows loc
In enforceVisualVoicemailPackage of PhoneInterfaceManager.java, there is a possible leak of visual voicemail package nam
User input included in error response, which could be used in a phishing attack.
IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could allow a remote attacker to obtain sensitive information when a
node-etsy-client is a NodeJs Etsy ReST API Client. Applications that are using node-etsy-client and reporting client err
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, a non admin user can get access to m
IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could allow a remote attacker to obtain sensitive information whe
IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed techni
A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `re
In SapphireIMS 4097_1, it is possible to guess the registered/active usernames of the software from the errors it gives
When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the conten
An information disclosure vulnerability in ILIAS before 5.3.19, 5.4.12 and 6.0 allows remote authenticated attackers to
IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an e
E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the abil
In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle errors at multiple locations
Triggering an error page of the import process in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS u
Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading ext
Exposure of System Data to an Unauthorized Control Sphere vulnerability in web UI of Argo CD allows attacker to cause le
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to access sensitive inf
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow
IBM Emptoris Contract Management and IBM Emptoris Spend Analysis 10.1.0, 10.1.1, and 10.1.3 could allow a remote attacke
IBM Security Guardium Insights 2.0.2 could allow a remote attacker to obtain sensitive information when a detailed techn
IBM Security Guardium Insights 2.0.2 could allow a remote attacker to obtain sensitive information when a detailed techn
IBM Cloud Pak for Security (CP4S) 1.3.0.1 and 1.4.0.0 could allow a remote attacker to obtain sensitive information when
A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are retu
An Information Disclosure vulnerability exists in dhcms 2017-09-18 when entering invalid characters after the normal int
The JSON web services in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 2
IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed techni
IBM Security Guardium 11.2 could allow a remote attacker to obtain sensitive information when a detailed technical error
SSL Network Extender Client for Linux before build 800008302 reveals part of the contents of the configuration file supp
Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-messag
White Shark System (WSS) 1.3.2 has web site physical path leakage vulnerability.
Shopware is an open source eCommerce platform. Versions prior to 5.6.10 are vulnerable to system information leakage in
A vulnerability has been identified in Teamcenter Active Workspace V4 (All versions < V4.3.9), Teamcenter Active Workspa
UCMS 1.5.0 was discovered to contain a physical path leakage via an error message returned by the adminchannelscache() f
IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensi
IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensi
IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 could allow a remote attacker to obtain sensitive information
The public share controller in the ownCloud server before version 10.8.0 allows a remote attacker to see the internal pa
Nextcloud Text is an open source plaintext editing application which ships with the nextcloud server. In affected versio
/way4acs/enroll in OpenWay WAY4 ACS before 1.2.278-2693 allows unauthenticated attackers to leverage response difference
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information
IBM Tivoli Key Lifecycle Manager (IBM Security Guardium Key Lifecycle Manager) 3.0, 3.0.1, 4.0, and 4.1 could allow a re
An issue was discovered in /goform/login_process in Reprise RLM 14.2. When an attacker attempts to login, the response i
livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information
IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical err
Frequently Asked Questions
What is CWE-209?
CWE-209 (CWE-209) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-209?
There are 697 CVE records associated with CWE-209 in our database. Of these, 27 are critical severity, 74 are high severity, and 394 are medium severity.
How can I protect against CWE-209 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-209 using AI-powered security agents.
Detect CWE-209 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-209 vulnerabilities across your infrastructure.
Get Started