Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in elfsight elfsight Contact Fo
An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
Unauthorized users can access INFINITT PACS System Manager without proper authorization, which could lead to unauthoriz
A GUI dialog of an application allows to view what files are in the file system without proper authorization.
Prior to September 19, 2025, the Hospital Manager Backend Services exposed the ASP.NET tracing endpoint /trace.axd witho
Student Learning Assessment and Support System developed by JHENG GAO has a Exposure of Sensitive Information vulnerabil
AVideo versions prior to 20.1 disclose absolute filesystem paths via multiple public API endpoints. Returned metadata in
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in wpweb Follow My Blog Post fo
A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorizatio
Information disclosure while exposing internal TA-to-TA communication APIs to HLOS
IBM Watson Query on Cloud Pak for Data (IBM Data Virtualization 1.8, 2.0, 2.1, 2.2, and 3.0.0) could allow an authentica
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in maennchen1.de m1.DownloadLis
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ThemeAtelier IDonatePro idon
Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Nept
Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose sensitive user account information (includ
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in jetmonsters Restaurant Menu
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in masteriyo Masteriyo - LMS le
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in GetResponse Email marketing
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs WP ERP erp allows Ret
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vikas Ratudi VPSUForm v-form
SAP GUI for Windows stores user input on the client PC to improve usability. Under very specific circumstances an attack
SAP GUI for Java saves user input on the client PC to improve usability. An attacker with administrative privileges or a
Applications based on SAP GUI for HTML in SAP NetWeaver Application Server ABAP store user input in the local browser st
The ed25519-dalek crate before 2 for Rust allows a double public key signing function oracle attack. The Keypair impleme
An authenticated user without user-management permissions could identify other user accounts.
A flaw was found in the FreeIPA API audit, where it sends the whole FreeIPA command line to journalctl. As a consequence
Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, contain(s) an Exposure of Sensitive System Infor
When the AWS Cloud Development Kit (AWS CDK) Command Line Interface (AWS CDK CLI) is used with a credential plugin which
Exposure of file path, file size or file existence vulnerabilities in ASPECT provide attackers access to file system inf
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in esigngenie Foxit eSign for W
Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to a
The issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sens
IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could disclose sensitive system information to an unauthori
IBM Security ReaQta 3.12 returns sensitive information in an HTTP response that could be used in further attacks against
IBM InfoSphere Information Server 11.7 could allow a remote user to obtain sensitive version information that could aid
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RebelCode Spotlight Social M
A vulnerability in langchain-core versions >=0.1.17,<0.1.53, >=0.2.0,<0.2.43, and >=0.3.0,<0.3.15 allows unauthorized us
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Beee ACF City Selector acf-c
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in J. Tyler Wiest Jetpack Feedb
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ERA404 StaffList stafflist a
IBM Aspera Console 3.4.0 through 3.4.4 could disclose sensitive information in HTTP headers that could be used in furthe
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in mediavine Mediavine Control
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Markus Drubba wpLike2Get wpl
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs weMail wemail allows
Files to be deployed with agents are accessible without authentication in Checkmk 2.1.0, Checkmk 2.2.0, Checkmk 2.3.0 an
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within th
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Solid Plugins AnalyticsWP al
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in whassan KI Live Video Confer
Umbraco, a free and open source .NET content management system, has a vulnerability in versions 10.0.0 through 10.8.10 a
Frequently Asked Questions
What is CWE-497?
CWE-497 (CWE-497) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-497?
There are 382 CVE records associated with CWE-497 in our database. Of these, 14 are critical severity, 68 are high severity, and 249 are medium severity.
How can I protect against CWE-497 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-497 using AI-powered security agents.
Detect CWE-497 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-497 vulnerabilities across your infrastructure.
Get Started