Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-497

MITRE ↗

CWE-497

14
CRITICAL
68
HIGH
249
MEDIUM
28
LOW
382 CVEs · Page 7/8
CVE-2025-4364

The affected products could allow an unauthenticated attacker to access system information that could enable further acc

CVE-2025-2236

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in OpenText Advanced Authentica

CVE-2025-4229

An information disclosure vulnerability in the SD-WAN feature of Palo Alto Networks PAN-OS® software enables an unauthor

CVE-2025-8597

MacVim's configuration on macOS, specifically the presence of entitlement "com.apple.security.get-task-allow", allows lo

CVE-2025-8700

Invoice Ninja's configuration on macOS, specifically the presence of entitlement "com.apple.security.get-task-allow", al

CVE-2025-4235

An information exposure vulnerability in the Palo Alto Networks User-ID Credential Agent (Windows-based) can expose the

CVE-2025-34156

Tibbo AggreGate Network Manager < 6.40.05 exposes sensitive system information through an unauthenticated endpoint at /c

CVE-2022-4985

Vodafone H500s devices running firmware v3.5.10 (hardware model Sercomm VFH500) expose the WiFi access point password vi

CVE-2025-11545

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sharp Display Solutions proj

9.6
CVE-2024-4008

FDSK Leak in ABB, Busch-Jaeger, FTS Display (version 1.00) and BCU (version 1.3.0.33) allows attacker to take control vi

8.8
CVE-2024-39675

A vulnerability has been identified in RUGGEDCOM RMC30 (All versions < V4.3.10), RUGGEDCOM RMC30NC (All versions < V4.3.

7.5
CVE-2024-31887

IBM Security Verify Privilege 11.6.25 could allow an unauthenticated actor to obtain sensitive information from the SOAP

7.5
CVE-2024-36070

tine before 2023.11.8, when an LDAP backend is used, allows anonymous remote attackers to obtain sensitive authenticatio

7.5
CVE-2024-5735

Full Path Disclosure vulnerability in AdmirorFrames Joomla! extension in afHelper.php script allows an unauthorised atta

7.5
CVE-2024-48024

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Fahad Mahmood Keep Backup Da

7.5
CVE-2024-50528

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Bui

7.5
CVE-2024-54279

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tobias Keller WP-NERD Toolki

7.4
CVE-2024-22125

Under certain conditions the Microsoft Edge browser extension (SAP GUI connector for Microsoft Edge) - version 1.0, allo

7.2
CVE-2024-25634

alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, an attacker can access data from other

7.1
CVE-2024-8687

An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user

6.5
CVE-2023-4605

A valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoin

6.5
CVE-2022-4968

netplan leaks the private key of wireguard to local users. Versions after 1.0 are not affected.

6.5
CVE-2024-50425

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Roland Murg WP Booking Syste

6.5
CVE-2024-53814

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Adnan Analytify wp-analytify

5.9
CVE-2024-6388

Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivil

5.9
CVE-2024-52321

Multiple SHARP routers contain an improper authentication vulnerability in the configuration backup function. The produc

5.5
CVE-2023-50180

An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiADC versio

5.5
CVE-2024-22037

The uyuni-server-attestation systemd service needs a database_password environment variable. This file has 640 permissio

5.4
CVE-2024-1809

The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to

5.3
CVE-2023-50959

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2,19.0.1, 19.0.2, 19.0.3,20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0

5.3
CVE-2024-3774

aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restriction

5.3
CVE-2024-31223

Fides is an open-source privacy engineering platform, and `SERVER_SIDE_FIDES_API_URL` is a server-side configuration env

5.3
CVE-2024-49252

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in VaultDweller Leyka leyka.Thi

5.3
CVE-2021-1234

A vulnerability in the cluster management interface of Cisco&nbsp;SD-WAN vManage Software could allow an unauthenticated

5.3
CVE-2024-52033

Exposure of sensitive system information to an unauthorized control sphere issue exists in Rakuten Turbo 5G firmware ver

5.3
CVE-2024-10240

An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting

5.3
CVE-2024-53768

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ideinteractive Content Audit

5.3
CVE-2024-25035

IBM Cognos Controller 11.0.0 and 11.0.1 exposes server details that could allow an attacker to obtain information of

5.3
CVE-2024-32732

Under certain conditions SAP BusinessObjects Business Intelligence platform allows an attacker to access information whi

5.1
CVE-2024-41781

IBM PowerVM Platform KeyStore (IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1030.00 through FW1030.60, FW1050.00

4.7
CVE-2024-52582

Cachi2 is a command-line interface tool that pre-fetches a project's dependencies to aid in making the project's build p

4.3
CVE-2024-31419

An information disclosure flaw was found in OpenShift Virtualization. The DownwardMetrics feature was introduced to expo

4.3
CVE-2024-39740

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 displays version information in HTTP requests that could all

4.3
CVE-2024-6389

An issue was discovered in GitLab-CE/EE affecting all versions starting with 17.0 before 17.1.7, 17.2 before 17.2.5, and

4.3
CVE-2024-37070

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to obtain sensitive information

4.3
CVE-2024-9929

A vulnerability exists in NSD570 that allows any authenticated user to access all device logs disclosing login informati

4.3
CVE-2024-53867

Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0

4.2
CVE-2024-36509

An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiWeb versio

4.1
CVE-2024-22124

Under certain conditions, Internet Communication Manager (ICM) or SAP Web Dispatcher - versions KERNEL 7.22, KERNEL 7.53

3.5
CVE-2024-47799

Exposure of sensitive system information to an unauthorized control sphere issue exists in Mesh Wi-Fi router RP562B firm

Frequently Asked Questions

What is CWE-497?

CWE-497 (CWE-497) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-497?

There are 382 CVE records associated with CWE-497 in our database. Of these, 14 are critical severity, 68 are high severity, and 249 are medium severity.

How can I protect against CWE-497 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-497 using AI-powered security agents.

Detect CWE-497 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-497 vulnerabilities across your infrastructure.

Get Started