Show filters
138 Total Results
Displaying 31-40 of 138
Sort by:
Attacker Value
Unknown

CVE-2021-32775

Disclosure Date: July 21, 2021 (last updated February 23, 2025)
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, a non admin user can get access to many class/field values through GroupBy Dashlet error message. This issue is fixed in versions 2.7.4 and 3.0.0.
Attacker Value
Unknown

CVE-2021-22145

Disclosure Date: July 21, 2021 (last updated February 23, 2025)
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.
Attacker Value
Unknown

CVE-2021-33711

Disclosure Date: July 13, 2021 (last updated February 23, 2025)
A vulnerability has been identified in Teamcenter Active Workspace V4 (All versions < V4.3.9), Teamcenter Active Workspace V5.0 (All versions < V5.0.7), Teamcenter Active Workspace V5.1 (All versions < V5.1.4). The affected application allows verbose error messages which allow leaking of sensitive information, such as full paths.
Attacker Value
Unknown

CVE-2021-20523

Disclosure Date: July 13, 2021 (last updated February 23, 2025)
IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 198660
Attacker Value
Unknown

CVE-2021-20499

Disclosure Date: July 13, 2021 (last updated February 23, 2025)
IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 197973
Attacker Value
Unknown

CVE-2021-32734

Disclosure Date: July 12, 2021 (last updated February 23, 2025)
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, the Nextcloud Text application shipped with Nextcloud Server returned verbatim exception messages to the user. This could result in a full path disclosure on shared files. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. As a workaround, one may disable the Nextcloud Text application in Nextcloud Server app settings.
Attacker Value
Unknown

CVE-2021-20424

Disclosure Date: July 12, 2021 (last updated February 23, 2025)
IBM Cloud Pak for Applications 4.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. X-Force ID: 196309.
Attacker Value
Unknown

CVE-2021-20417

Disclosure Date: July 06, 2021 (last updated February 23, 2025)
IBM Guardium Data Encryption (GDE) 4.0.0.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196219
Attacker Value
Unknown

CVE-2021-20413

Disclosure Date: June 25, 2021 (last updated February 22, 2025)
IBM Guardium Data Encryption (GDE) 4.0.0.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196212.
Attacker Value
Unknown

CVE-2021-32712

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
Shopware is an open source eCommerce platform. Versions prior to 5.6.10 are vulnerable to system information leakage in error handling. Users are recommend to update to version 5.6.10. You can get the update to 5.6.10 regularly via the Auto-Updater or directly via the download overview.