CWE-209
AllowedGeneration of Error Message Containing Sensitive Information
Abstraction: Base · Status: Draft
The product generates an error message that includes sensitive information about its environment, users, or associated data.
950 vulnerabilities reference this CWE, most recent first.
GHSA-MQ92-JR35-FFPC
Vulnerability from github – Published: 2024-10-09 21:31 – Updated: 2026-09-02 14:29Withdrawn Advisory
This advisory has been withdrawn because it does not describe a valid vulnerability. This link is maintained to preserve external references.
Original Description
An information disclosure vulnerability exists in open-webui version 0.3.8. The vulnerability is related to the embedding model update feature under admin settings. When a user updates the model path, the system checks if the file exists and provides different error messages based on the existence and configuration of the file. This behavior allows an attacker to enumerate file names and traverse directories by observing the error messages, leading to potential exposure of sensitive information.
{
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "open-webui"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "0.3.8"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2024-7038"
],
"database_specific": {
"cwe_ids": [
"CWE-200",
"CWE-209"
],
"github_reviewed": true,
"github_reviewed_at": "2024-10-09T22:07:49Z",
"nvd_published_at": "2024-10-09T19:15:14Z",
"severity": "LOW"
},
"details": "### Withdrawn Advisory\nThis advisory has been withdrawn because it does not describe a valid vulnerability. This link is maintained to preserve external references.\n\n### Original Description\nAn information disclosure vulnerability exists in open-webui version 0.3.8. The vulnerability is related to the embedding model update feature under admin settings. When a user updates the model path, the system checks if the file exists and provides different error messages based on the existence and configuration of the file. This behavior allows an attacker to enumerate file names and traverse directories by observing the error messages, leading to potential exposure of sensitive information.",
"id": "GHSA-mq92-jr35-ffpc",
"modified": "2026-09-02T14:29:24Z",
"published": "2024-10-09T21:31:08Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7038"
},
{
"type": "PACKAGE",
"url": "https://github.com/open-webui/open-webui"
},
{
"type": "WEB",
"url": "https://github.com/open-webui/open-webui/blob/eff736acd2e0bbbdd0eeca4cc209b216a1f23b6a/backend/apps/rag/main.py#L199"
},
{
"type": "WEB",
"url": "https://huntr.com/bounties/f42cf72a-8015-44a6-81a9-c6332ef05afc"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
"type": "CVSS_V4"
}
],
"summary": "Withdrawn Advisory: open-webui allows enumeration of file names and traversal of directories by observing the error messages",
"withdrawn": "2026-09-02T14:29:23Z"
}
GHSA-MV89-P3H4-X57H
Vulnerability from github – Published: 2022-05-24 19:02 – Updated: 2022-06-29 00:00An information disclosure vulnerability in ILIAS before 5.3.19, 5.4.12 and 6.0 allows remote authenticated attackers to get the upload data path via a workspace upload.
{
"affected": [],
"aliases": [
"CVE-2020-23995"
],
"database_specific": {
"cwe_ids": [
"CWE-200",
"CWE-209"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2021-05-13T20:15:00Z",
"severity": "MODERATE"
},
"details": "An information disclosure vulnerability in ILIAS before 5.3.19, 5.4.12 and 6.0 allows remote authenticated attackers to get the upload data path via a workspace upload.",
"id": "GHSA-mv89-p3h4-x57h",
"modified": "2022-06-29T00:00:31Z",
"published": "2022-05-24T19:02:18Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-23995"
},
{
"type": "WEB",
"url": "https://github.com/ILIAS-eLearning/ILIAS/commit/94d9b16010ec3abeae8d2cbb05622ccd999119ad"
},
{
"type": "WEB",
"url": "https://cwe.mitre.org/data/definitions/209.html"
},
{
"type": "WEB",
"url": "https://docu.ilias.de/goto_docu_pg_118817_35.html"
},
{
"type": "WEB",
"url": "https://docu.ilias.de/goto_docu_pg_122177_35.html"
},
{
"type": "WEB",
"url": "https://docu.ilias.de/goto_docu_pg_124761_35.html"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-MX2R-33GR-HH84
Vulnerability from github – Published: 2024-07-17 00:32 – Updated: 2024-07-17 00:32IBM Sterling Partner Engagement Manager 6.2.2 could allow a local attacker to obtain sensitive information when a detailed technical error message is returned. IBM X-Force ID: 230933.
{
"affected": [],
"aliases": [
"CVE-2022-35640"
],
"database_specific": {
"cwe_ids": [
"CWE-209"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-16T23:15:10Z",
"severity": "MODERATE"
},
"details": "IBM Sterling Partner Engagement Manager 6.2.2 could allow a local attacker to obtain sensitive information when a detailed technical error message is returned. IBM X-Force ID: 230933.",
"id": "GHSA-mx2r-33gr-hh84",
"modified": "2024-07-17T00:32:54Z",
"published": "2024-07-17T00:32:54Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-35640"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/230933"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7160300"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-MX8Q-JQWM-85MV
Vulnerability from github – Published: 2022-06-14 00:00 – Updated: 2023-06-30 20:40In NocoDB prior to 0.91.7, the SMTP plugin doesn't have verification or validation. This allows attackers to make requests to internal servers and read the contents.
{
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "nocodb"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.91.7"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2022-2062"
],
"database_specific": {
"cwe_ids": [
"CWE-200",
"CWE-209",
"CWE-918"
],
"github_reviewed": true,
"github_reviewed_at": "2023-06-30T20:40:22Z",
"nvd_published_at": "2022-06-13T12:15:00Z",
"severity": "HIGH"
},
"details": "In NocoDB prior to 0.91.7, the SMTP plugin doesn\u0027t have verification or validation. This allows attackers to make requests to internal servers and read the contents.",
"id": "GHSA-mx8q-jqwm-85mv",
"modified": "2023-06-30T20:40:22Z",
"published": "2022-06-14T00:00:37Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2062"
},
{
"type": "WEB",
"url": "https://github.com/nocodb/nocodb/commit/a18f5dd53811b9ec1c1bb2fdbfb328c0c87d7fb4"
},
{
"type": "PACKAGE",
"url": "https://github.com/nocodb/nocodb"
},
{
"type": "WEB",
"url": "https://huntr.dev/bounties/35593b4c-f127-4699-8ad3-f0b2203a8ef6"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
],
"summary": "NocoDB information disclosure vulnerability"
}
GHSA-MX95-7G4V-PPPJ
Vulnerability from github – Published: 2023-08-25 09:30 – Updated: 2024-04-04 07:12e-Excellence U-Office Force generates an error message in webiste service. An unauthenticated remote attacker can obtain partial sensitive system information from error message by sending a crafted command.
{
"affected": [],
"aliases": [
"CVE-2023-32755"
],
"database_specific": {
"cwe_ids": [
"CWE-209"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-08-25T07:15:08Z",
"severity": "MODERATE"
},
"details": "\ne-Excellence U-Office Force generates an error message in webiste service. An unauthenticated remote attacker can obtain partial sensitive system information from error message by sending a crafted command.\n\n",
"id": "GHSA-mx95-7g4v-pppj",
"modified": "2024-04-04T07:12:12Z",
"published": "2023-08-25T09:30:20Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32755"
},
{
"type": "WEB",
"url": "https://www.twcert.org.tw/tw/cp-132-7328-d4112-1.html"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-P5MM-XWGQ-WHFR
Vulnerability from github – Published: 2026-06-10 00:31 – Updated: 2026-08-12 17:42Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persistence-layer internals to HTTP clients.
Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 through 4.4.14; 4.5.0 through 4.5.11; 5.0.0 through 5.0.5.
{
"affected": [
{
"database_specific": {
"last_known_affected_version_range": "\u003c= 5.0.5"
},
"package": {
"ecosystem": "Maven",
"name": "org.springframework.data:spring-data-rest-core"
},
"ranges": [
{
"events": [
{
"introduced": "5.0.0"
},
{
"fixed": "5.0.6"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"database_specific": {
"last_known_affected_version_range": "\u003c= 4.5.11"
},
"package": {
"ecosystem": "Maven",
"name": "org.springframework.data:spring-data-rest-core"
},
"ranges": [
{
"events": [
{
"introduced": "4.5.0"
},
{
"fixed": "4.5.12"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.springframework.data:spring-data-rest-core"
},
"ranges": [
{
"events": [
{
"introduced": "4.4.0"
},
{
"last_affected": "4.4.14"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.springframework.data:spring-data-rest-core"
},
"ranges": [
{
"events": [
{
"introduced": "4.3.0"
},
{
"last_affected": "4.3.16"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.springframework.data:spring-data-rest-core"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "3.7.19"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-41730"
],
"database_specific": {
"cwe_ids": [
"CWE-209"
],
"github_reviewed": true,
"github_reviewed_at": "2026-08-12T17:42:43Z",
"nvd_published_at": "2026-06-10T00:16:52Z",
"severity": "MODERATE"
},
"details": "Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persistence-layer internals to HTTP clients.\n\nAffected versions:\nSpring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 through 4.4.14; 4.5.0 through 4.5.11; 5.0.0 through 5.0.5.",
"id": "GHSA-p5mm-xwgq-whfr",
"modified": "2026-08-12T17:42:43Z",
"published": "2026-06-10T00:31:52Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41730"
},
{
"type": "PACKAGE",
"url": "https://github.com/spring-projects/spring-data-rest"
},
{
"type": "WEB",
"url": "https://github.com/spring-projects/spring-data-rest/releases/tag/4.5.12"
},
{
"type": "WEB",
"url": "https://github.com/spring-projects/spring-data-rest/releases/tag/5.0.6"
},
{
"type": "WEB",
"url": "https://spring.io/security/cve-2026-41730"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
}
],
"summary": "Spring Data REST potentially exposes persistence-layer internals to HTTP clients"
}
GHSA-P72J-QJHF-94M3
Vulnerability from github – Published: 2026-04-15 15:31 – Updated: 2026-04-15 15:31HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem structures. Exposure of such information may provide insights into the underlying environment, which could potentially aid in further targeted actions or limited information disclosure.
{
"affected": [],
"aliases": [
"CVE-2025-52641"
],
"database_specific": {
"cwe_ids": [
"CWE-209"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-04-15T09:16:31Z",
"severity": "LOW"
},
"details": "HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem structures. Exposure of such information may provide insights into the underlying environment, which could potentially aid in further targeted actions or limited information disclosure.",
"id": "GHSA-p72j-qjhf-94m3",
"modified": "2026-04-15T15:31:41Z",
"published": "2026-04-15T15:31:41Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-52641"
},
{
"type": "WEB",
"url": "https://support.hcl-software.com/csm?id=kb_article\u0026sysparm_article=KB0130007"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-P72W-R6FV-6G5H
Vulnerability from github – Published: 2024-09-17 21:30 – Updated: 2025-03-14 21:41Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to manipulate a pac4j session cookie.
This issue affects Apache Druid versions 0.18.0 through 30.0.0. Since the druid-pac4j extension is optional and disabled by default, Druid installations not using the druid-pac4j extension are not affected by this vulnerability.
While we are not aware of a way to meaningfully exploit this flaw, we nevertheless recommend upgrading to version 30.0.1 or higher which fixes the issue and ensuring you have a strong druid.auth.pac4j.cookiePassphrase as a precaution.
{
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.druid.extensions:druid-pac4j"
},
"ranges": [
{
"events": [
{
"introduced": "0.18.0"
},
{
"fixed": "30.0.1"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2024-45384"
],
"database_specific": {
"cwe_ids": [
"CWE-209",
"CWE-347"
],
"github_reviewed": true,
"github_reviewed_at": "2024-09-17T22:14:49Z",
"nvd_published_at": "2024-09-17T19:15:28Z",
"severity": "LOW"
},
"details": "Padding Oracle vulnerability in Apache Druid extension, druid-pac4j.\nThis could allow an attacker to manipulate a pac4j session cookie.\n\nThis issue affects Apache Druid versions 0.18.0 through 30.0.0.\nSince the druid-pac4j extension is optional and disabled by default, Druid installations not using the druid-pac4j extension are not affected by this vulnerability.\n\nWhile we are not aware of a way to meaningfully exploit this flaw, we nevertheless recommend upgrading to version 30.0.1 or higher which fixes the issue and ensuring you have a strong druid.auth.pac4j.cookiePassphrase as a precaution.",
"id": "GHSA-p72w-r6fv-6g5h",
"modified": "2025-03-14T21:41:15Z",
"published": "2024-09-17T21:30:32Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45384"
},
{
"type": "WEB",
"url": "https://github.com/apache/druid/commit/74cab7a76c99da457c3a883939cc0b03301b8771"
},
{
"type": "PACKAGE",
"url": "https://github.com/apache/druid"
},
{
"type": "WEB",
"url": "https://github.com/apache/druid/releases/tag/druid-30.0.1"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread/gr94fnp574plb50lsp8jw4smvgv1lbz1"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/09/17/1"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U",
"type": "CVSS_V4"
}
],
"summary": "druid-pac4j, Apache Druid extension, has Padding Oracle vulnerability"
}
GHSA-P74C-JF66-6RW3
Vulnerability from github – Published: 2022-05-24 19:05 – Updated: 2022-05-24 19:05E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to discover information via error messaging which may aid in crafting more complex attacks.
{
"affected": [],
"aliases": [
"CVE-2021-26997"
],
"database_specific": {
"cwe_ids": [
"CWE-209"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2021-06-11T13:15:00Z",
"severity": "MODERATE"
},
"details": "E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to discover information via error messaging which may aid in crafting more complex attacks.",
"id": "GHSA-p74c-jf66-6rw3",
"modified": "2022-05-24T19:05:11Z",
"published": "2022-05-24T19:05:11Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-26997"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/NTAP-20210610-0004"
}
],
"schema_version": "1.4.0",
"severity": []
}
GHSA-P7HP-79JJ-Q923
Vulnerability from github – Published: 2026-07-20 12:33 – Updated: 2026-09-04 20:07Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-6g9v-7gq3-p2c6. This link is maintained to preserve external references.
Original Description
SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with UPDATE access can read field values hidden by field-level SELECT permissions through error messages. Attackers can trigger arithmetic or extend operations on hidden fields to embed raw operand values in error responses, bypassing field-level access controls.
{
"affected": [
{
"database_specific": {
"last_known_affected_version_range": "\u003c 3.1.0"
},
"package": {
"ecosystem": "crates.io",
"name": "surrealdb"
},
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [],
"database_specific": {
"cwe_ids": [
"CWE-209"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-04T20:07:31Z",
"nvd_published_at": "2026-07-20T12:19:44Z",
"severity": "MODERATE"
},
"details": "## Duplicate Advisory\n\nThis advisory has been withdrawn because it is a duplicate of\u00a0GHSA-6g9v-7gq3-p2c6. This link is maintained to preserve external references.\n\n## Original Description\n\nSurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with UPDATE access can read field values hidden by field-level SELECT permissions through error messages. Attackers can trigger arithmetic or extend operations on hidden fields to embed raw operand values in error responses, bypassing field-level access controls.",
"id": "GHSA-p7hp-79jj-q923",
"modified": "2026-09-04T20:07:31Z",
"published": "2026-07-20T12:33:09Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-6g9v-7gq3-p2c6"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63748"
},
{
"type": "WEB",
"url": "https://www.vulncheck.com/advisories/surrealdb-before-information-disclosure-via-error-messages"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
],
"summary": "Duplicate Advisory: SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages",
"withdrawn": "2026-09-04T20:07:31Z"
}
Mitigation MIT-39
- Ensure that error messages only contain minimal details that are useful to the intended audience and no one else. The messages need to strike the balance between being too cryptic (which can confuse users) or being too detailed (which may reveal more than intended). The messages should not reveal the methods that were used to determine the error. Attackers can use detailed information to refine or optimize their original attack, thereby increasing their chances of success.
- If errors must be captured in some detail, record them in log messages, but consider what could occur if the log messages can be viewed by attackers. Highly sensitive information such as passwords should never be saved to log files.
- Avoid inconsistent messaging that might accidentally tip off an attacker about internal state, such as whether a user account exists or not.
Mitigation
Handle exceptions internally and do not display errors containing potentially sensitive information to a user.
Mitigation MIT-33
Strategy: Attack Surface Reduction
Use naming conventions and strong types to make it easier to spot when sensitive data is being used. When creating structures, objects, or other complex entities, separate the sensitive and non-sensitive data as much as possible.
Mitigation MIT-40
Strategy: Compilation or Build Hardening
Debugging information should not make its way into a production release.
Mitigation MIT-40
Strategy: Environment Hardening
Debugging information should not make its way into a production release.
Mitigation
Where available, configure the environment to use less verbose error messages. For example, in PHP, disable the display_errors setting during configuration, or at runtime using the error_reporting() function.
Mitigation
Create default error pages or messages that do not leak any information.
CAPEC-215: Fuzzing for application mapping
An attacker sends random, malformed, or otherwise unexpected messages to a target application and observes the application's log or error messages returned. The attacker does not initially know how a target will respond to individual messages but by attempting a large number of message variants they may find a variant that trigger's desired behavior. In this attack, the purpose of the fuzzing is to observe the application's log and error messages, although fuzzing a target can also sometimes cause the target to enter an unstable state, causing a crash.
CAPEC-463: Padding Oracle Crypto Attack
An adversary is able to efficiently decrypt data without knowing the decryption key if a target system leaks data on whether or not a padding error happened while decrypting the ciphertext. A target system that leaks this type of information becomes the padding oracle and an adversary is able to make use of that oracle to efficiently decrypt data without knowing the decryption key by issuing on average 128*b calls to the padding oracle (where b is the number of bytes in the ciphertext block). In addition to performing decryption, an adversary is also able to produce valid ciphertexts (i.e., perform encryption) by using the padding oracle, all without knowing the encryption key.
CAPEC-54: Query System for Information
An adversary, aware of an application's location (and possibly authorized to use the application), probes an application's structure and evaluates its robustness by submitting requests and examining responses. Often, this is accomplished by sending variants of expected queries in the hope that these modified queries might return information beyond what the expected set of queries would provide.
CAPEC-7: Blind SQL Injection
Blind SQL Injection results from an insufficient mitigation for SQL Injection. Although suppressing database error messages are considered best practice, the suppression alone is not sufficient to prevent SQL Injection. Blind SQL Injection is a form of SQL Injection that overcomes the lack of error messages. Without the error messages that facilitate SQL Injection, the adversary constructs input strings that probe the target through simple Boolean SQL expressions. The adversary can determine if the syntax and structure of the injection was successful based on whether the query was executed or not. Applied iteratively, the adversary determines how and where the target is vulnerable to SQL Injection.