An information disclosure vulnerability was reported in the Lenovo Tab M8 HD that could allow a local application to gat
In getCustomPrinterIcon of PrintManagerService.java, there is a possible way to view other user's images due to a confus
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 could disclose sensitiv
IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authenticated user to obtain
A vulnerability in Cortex XSOAR allows the disclosure of incident data to users who do not have the privilege to view th
Infinix devices contain a pre-loaded "com.rlk.weathers" application, that exposes an unsecured content provider. An atta
Landscape's server-status page exposed sensitive system information. This data leak included GET requests which contain
A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the priv
Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a Exposure of Sensitive System I
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat
The Web Frontend of KNIME Business Hub before 1.4.0 allows an unauthenticated remote attacker to access internals about
SAP Business One (Service Layer) - version 10.0, allows an authenticated attacker with deep knowledge perform certain op
Under certain condition SAP NetWeaver Application Server ABAP - versions KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7.
Exposure of Sensitive System Information to an Unauthorized Control Sphere in create template function in EasyUse MailHu
A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext val
MongoDB Ops Manager Diagnostics Archive may not redact sensitive PEM key file password app settings. Archives do not inc
A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized i
In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields
A vulnerability in the web management interface of Cisco Secure Email and Web Manager, formerly Cisco Security Managemen
A credentials leak was found in the OpenShift Container Platform. The private key for the external cluster certificate w
IBM Robotic Process Automation 21.0.1 and 21.0.2 could disclose sensitive version to an unauthorized control sphere info
A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, local attacker to view sensitive informat
An improper authorization vulnerability in the Simple Network Management Protocol daemon (snmpd) service of Juniper Netw
An Exposure of System Data vulnerability in Juniper Networks Junos OS and Junos OS Evolved, where a sensitive system-lev
Exposure of System Data to an Unauthorized Control Sphere vulnerability in web UI of Argo CD allows attacker to cause le
A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to read sensiti
A vulnerability in logging mechanisms of Cisco Webex Meetings client software could allow an authenticated, local attack
Windows Kernel Information Disclosure Vulnerability
A vulnerability in the cluster management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, rem
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the net
A vulnerability in Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensit
In Eclipse Kura versions up to 4.0.0, Kura exposes the underlying Ui Web server version in its replies. This can be used
Frequently Asked Questions
What is CWE-497?
CWE-497 (CWE-497) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-497?
There are 382 CVE records associated with CWE-497 in our database. Of these, 14 are critical severity, 68 are high severity, and 249 are medium severity.
How can I protect against CWE-497 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-497 using AI-powered security agents.
Detect CWE-497 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-497 vulnerabilities across your infrastructure.
Get Started