CWE-550Variant

Server-generated Error Message Containing Sensitive Information

Incomplete in the CWE catalog · 4 CVEs mapped

4
CVEs mapped
7.1
Median CVSS
What it is

Certain conditions, such as network failure, will cause a server error message to be displayed.

Recent examples
5.3cvss
CVE-2025-36419

Multiple vulnerabilities found in IBM ApplinX.

IBM ApplinX 11.1 could disclose sensitive information about server architecture that could aid in further attacks against the system.

MEDIUMno explanation yet
0%
epss
10.0cvss
CVE-2025-62168

Squid vulnerable to information disclosure via authentication credential leakage in error handling

🚨 A sneaky oversight in Squid means HTTP authentication credentials can slip through error messages! 🔥 Think of it like a hotel receptionist who accidentally leaves the guest list out for everyone to see — that list contains all the guests' room keys, just waiting to be grabbed! An attacker could exploit this vulnerability to harvest sensitive authentication tokens from trusted clients. This could lead to unauthorized access or data leaks from web applications that rely on Squid for load balancing — a recipe for absolute chaos!

CRITICAL
63%
epss
5.3cvss
CVE-2023-5617

Hitachi Vantara Pentaho Data Integration & Analytics - Server-generated Error Message Containing Sensitive Information

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.6, including 9.5.x and 8.3.x, display the version of Tomcat when a server error is encountered.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-550
Abstraction
Variant
Structure
Simple
Status
Incomplete