Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in POSIMYTH Nexter Blocks the-p
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Dotstore Fraud Prevention Fo
Under certain conditions SAP S/4HANA (Manage Payment Media) allows an authenticated attacker to access information which
An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 26.4 and iP
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Softaculous PageLayer pagela
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Designinvento DirectoryPress
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in magepeopleteam Bus Ticket Bo
OpenClaw before 2026.4.2 exposes configPath and stateDir metadata in Gateway connect success snapshots to non-admin auth
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPFunnels Team Mail Mint all
The SAP Gateway allows attackers to inject content into error messages, potentially leading to disclosure of request art
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HashThemes Hash Elements all
Unauthenticated Sensitive Data Exposure in Bopo – WooCommerce Product Bundle Builder <= 1.1.6 versions.
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Chouby Polylang and Chouby P
Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.
SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagn
IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and I
HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal config
Under certain conditions, when an unauthorized attacker accesses a specific endpoint, SAP Business Objects application l
IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive information about o
The lack of hardening of the system allows the user used to manage and maintain the charger to consult different files c
The Access Manager is offering a trace functionality to debug errors and issues with the device. The trace functionality
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Physical paths could be displ
An information disclosure vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to obta
SEPPmail Secure Email Gateway before version 15.0.4 exposes server environment variables through an unauthenticated endp
A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnera
Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:select
Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handl
TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without sufficient protection. A ph
Certain models of NVR developed by Digiever has an Exposure of Sensitive Information vulnerability, allowing unauthentic
Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagi
Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) in the Gallagher Morpho integration
Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me KW-60 R36
School Affairs System from Quanxun has an Exposure of Sensitive Information, allowing unauthenticated attackers to view
Smart Parking Management System from Honding Technology has an Exposure of Sensitive Information vulnerability, allowing
Certain hybrid DVR models ((HBF-09KD and HBF-16NK)) from Hunt Electronic have an Exposure of Sensitive Information vulne
Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP
An open database issue exists in the affected product and version. The security issue stems from an over permissive Redi
Nagios XI versions prior to 2024R1.1.2 may (confirmed in 2024R1.1 and 2024R1.1.1) disclose sensitive user account inform
Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8,
SAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to perform session hijacking over
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vegagrup Software Vega Maste
Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Sensitive System Information to an Unauthorized
VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privil
Information disclosure while creating MQ channels.
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: EMC). Sup
A Local File Inclusion (LFI) vulnerability exists in the /load-workflow endpoint of modelscope/agentscope version v0.0.4
Information disclosure of authentication information in the specific service vulnerability exists in Wi-Fi AP UNIT 'AC-W
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in NotFound Macro Calculator wi
Vestel AC Charger version 3.75.0 contains a vulnerability that could enable an attacker to access files containing s
Frequently Asked Questions
What is CWE-497?
CWE-497 (CWE-497) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-497?
There are 382 CVE records associated with CWE-497 in our database. Of these, 14 are critical severity, 68 are high severity, and 249 are medium severity.
How can I protect against CWE-497 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-497 using AI-powered security agents.
Detect CWE-497 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-497 vulnerabilities across your infrastructure.
Get Started