The affected products could allow an unauthenticated attacker to access system information that could enable further acc
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in OpenText Advanced Authentica
An information disclosure vulnerability in the SD-WAN feature of Palo Alto Networks PAN-OS® software enables an unauthor
MacVim's configuration on macOS, specifically the presence of entitlement "com.apple.security.get-task-allow", allows lo
Invoice Ninja's configuration on macOS, specifically the presence of entitlement "com.apple.security.get-task-allow", al
An information exposure vulnerability in the Palo Alto Networks User-ID Credential Agent (Windows-based) can expose the
Tibbo AggreGate Network Manager < 6.40.05 exposes sensitive system information through an unauthenticated endpoint at /c
Vodafone H500s devices running firmware v3.5.10 (hardware model Sercomm VFH500) expose the WiFi access point password vi
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sharp Display Solutions proj
FDSK Leak in ABB, Busch-Jaeger, FTS Display (version 1.00) and BCU (version 1.3.0.33) allows attacker to take control vi
A vulnerability has been identified in RUGGEDCOM RMC30 (All versions < V4.3.10), RUGGEDCOM RMC30NC (All versions < V4.3.
IBM Security Verify Privilege 11.6.25 could allow an unauthenticated actor to obtain sensitive information from the SOAP
tine before 2023.11.8, when an LDAP backend is used, allows anonymous remote attackers to obtain sensitive authenticatio
Full Path Disclosure vulnerability in AdmirorFrames Joomla! extension in afHelper.php script allows an unauthorised atta
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Fahad Mahmood Keep Backup Da
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Bui
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tobias Keller WP-NERD Toolki
Under certain conditions the Microsoft Edge browser extension (SAP GUI connector for Microsoft Edge) - version 1.0, allo
alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, an attacker can access data from other
An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user
A valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoin
netplan leaks the private key of wireguard to local users. Versions after 1.0 are not affected.
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Roland Murg WP Booking Syste
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Adnan Analytify wp-analytify
Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivil
Multiple SHARP routers contain an improper authentication vulnerability in the configuration backup function. The produc
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiADC versio
The uyuni-server-attestation systemd service needs a database_password environment variable. This file has 640 permissio
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2,19.0.1, 19.0.2, 19.0.3,20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0
aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restriction
Fides is an open-source privacy engineering platform, and `SERVER_SIDE_FIDES_API_URL` is a server-side configuration env
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in VaultDweller Leyka leyka.Thi
A vulnerability in the cluster management interface of Cisco SD-WAN vManage Software could allow an unauthenticated
Exposure of sensitive system information to an unauthorized control sphere issue exists in Rakuten Turbo 5G firmware ver
An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ideinteractive Content Audit
IBM Cognos Controller 11.0.0 and 11.0.1 exposes server details that could allow an attacker to obtain information of
Under certain conditions SAP BusinessObjects Business Intelligence platform allows an attacker to access information whi
IBM PowerVM Platform KeyStore (IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1030.00 through FW1030.60, FW1050.00
Cachi2 is a command-line interface tool that pre-fetches a project's dependencies to aid in making the project's build p
An information disclosure flaw was found in OpenShift Virtualization. The DownwardMetrics feature was introduced to expo
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 displays version information in HTTP requests that could all
An issue was discovered in GitLab-CE/EE affecting all versions starting with 17.0 before 17.1.7, 17.2 before 17.2.5, and
IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to obtain sensitive information
A vulnerability exists in NSD570 that allows any authenticated user to access all device logs disclosing login informati
Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiWeb versio
Under certain conditions, Internet Communication Manager (ICM) or SAP Web Dispatcher - versions KERNEL 7.22, KERNEL 7.53
Exposure of sensitive system information to an unauthorized control sphere issue exists in Mesh Wi-Fi router RP562B firm
Frequently Asked Questions
What is CWE-497?
CWE-497 (CWE-497) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-497?
There are 382 CVE records associated with CWE-497 in our database. Of these, 14 are critical severity, 68 are high severity, and 249 are medium severity.
How can I protect against CWE-497 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-497 using AI-powered security agents.
Detect CWE-497 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-497 vulnerabilities across your infrastructure.
Get Started