Show filters
351 Total Results
Displaying 341-350 of 351
Sort by:
Attacker Value
Unknown
CVE-2019-11252
Disclosure Date: March 04, 2020 (last updated February 21, 2025)
The Kubernetes kube-controller-manager in versions v1.0-v1.17 is vulnerable to a credential leakage via error messages in mount failure logs and events for AzureFile and CephFS volumes.
0
Attacker Value
Unknown
CVE-2019-19993
Disclosure Date: February 26, 2020 (last updated February 21, 2025)
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Several full path disclosure vulnerability were discovered. A user, even with no authentication, may simply send arbitrary content to the vulnerable pages to generate error messages that expose some full paths.
0
Attacker Value
Unknown
CVE-2020-9351
Disclosure Date: February 23, 2020 (last updated February 21, 2025)
An issue was discovered in SmartClient 12.0. If an unauthenticated attacker makes a POST request to /tools/developerConsoleOperations.jsp or /isomorphic/IDACall with malformed XML data in the _transaction parameter, the server replies with a verbose error showing where the application resides (the absolute path). NOTE: the documentation states "These tools are, by default, available to anyone ... so they should only be deployed into a trusted environment. Alternately, the tools can easily be restricted to administrators or end users by protecting the tools path with normal authentication and authorization mechanisms on the web server."
0
Attacker Value
Unknown
CVE-2019-4583
Disclosure Date: February 19, 2020 (last updated February 21, 2025)
IBM Maximo Asset Management 7.6.0.10 and 7.6.1.1 could allow an authenticated user to obtain sensitive information from a stack trace that could be used to aid future attacks. IBM X-Force ID: 167289.
0
Attacker Value
Unknown
CVE-2018-21032
Disclosure Date: February 14, 2020 (last updated February 21, 2025)
A vulnerability in Hitachi Command Suite prior to 8.7.1-00 and Hitachi Automation Director prior to 8.5.0-00 allow authenticated remote users to expose technical information through error messages. Hitachi Command Suite includes Hitachi Device Manager and Hitachi Compute Systems Manager.
0
Attacker Value
Unknown
CVE-2020-6189
Disclosure Date: February 12, 2020 (last updated February 21, 2025)
Certain settings page(s) in SAP Business Objects Business Intelligence Platform (CMC), version 4.2, generates error messages that can give enterprise private-network related information which would otherwise be restricted leading to Information Disclosure.
0
Attacker Value
Unknown
CVE-2019-4636
Disclosure Date: January 28, 2020 (last updated February 21, 2025)
IBM Security Secret Server 10.7 could disclose sensitive information to an authenticated user from generated error messages. IBM X-Force ID: 170013.
0
Attacker Value
Unknown
CVE-2014-8161
Disclosure Date: January 27, 2020 (last updated February 21, 2025)
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.
0
Attacker Value
Unknown
CVE-2020-7231
Disclosure Date: January 19, 2020 (last updated February 21, 2025)
Evoko Home 1.31 devices provide different error messages for failed login requests depending on whether the username is valid.
0
Attacker Value
Unknown
CVE-2019-18947
Disclosure Date: November 21, 2019 (last updated February 22, 2025)
Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to information disclosure.
0