Vulnerabilities (CVE)

Filtered by CWE-209
Total 325 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-8042 1 Apache 1 Ambari 2019-10-03 4.3 MEDIUM 8.1 HIGH
Apache Ambari, version 2.5.0 to 2.6.2, passwords for Hadoop credential stores are exposed in Ambari Agent informational log messages when the credential store feature is enabled for eligible services. For example, Hive and Oozie.
CVE-2018-11325 1 Joomla 1 Joomla\! 2019-10-03 5.0 MEDIUM 9.8 CRITICAL
An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after either a form validation error or navigating to a previous install step, and display the plaintext password for the administrator account at the confirmation screen.
CVE-2017-1370 1 Ibm 1 Jazz Reporting Service 2019-10-03 4.0 MEDIUM 4.9 MEDIUM
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user credentials, through an error message from the Report Builder administrator configuration page. IBM X-Force ID: 126863.
CVE-2018-14925 1 Matera 1 Banco 2019-10-03 7.5 HIGH 9.8 CRITICAL
Matera Banco 1.0.0 mishandles Java errors in the backend, as demonstrated by a stack trace revealing use of net.sf.acegisecurity components.
CVE-2019-15032 1 Pydio 1 Pydio 2019-09-19 5.0 MEDIUM 5.3 MEDIUM
Pydio 6.0.8 mishandles error reporting when a directory allows unauthenticated uploads, and the remote-upload option is used with the http://localhost:22 URL. The attacker can obtain sensitive information such as the name of the user who created that directory and other internal server information.