
CVE-2024-42424
https://notcve.org/view.php?id=CVE-2024-42424
10 Sep 2024 — A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. • https://www.dell.com/support/kbdoc/en-us/000227014/dsa-2024-327 • CWE-20: Improper Input Validation •

CVE-2024-45283 – Information disclosure vulnerability in SAP NetWeaver AS for Java (Destination Service)
https://notcve.org/view.php?id=CVE-2024-45283
10 Sep 2024 — SAP NetWeaver AS for Java allows an authorized attacker to obtain sensitive information. ... After successful exploitation, an attacker can read the sensitive information but cannot modify or delete the data. • https://me.sap.com/notes/3477359 • CWE-256: Plaintext Storage of a Password •

CVE-2024-44121 – Information Disclosure in SAP S/4 HANA (Statutory Reports)
https://notcve.org/view.php?id=CVE-2024-44121
10 Sep 2024 — Under certain conditions Statutory Reports in SAP S/4 HANA allows an attacker with basic privileges to access information which would otherwise be restricted. • https://me.sap.com/notes/3437585 • CWE-213: Exposure of Sensitive Information Due to Incompatible Policies •

CVE-2024-44113 – Information Disclosure vulnerability in the SAP Business Warehouse (BEx Analyzer)
https://notcve.org/view.php?id=CVE-2024-44113
10 Sep 2024 — Due to missing authorization checks, SAP Business Warehouse (BEx Analyzer) allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation the attacker can enumerate information causing a limited impact on confidentiality of the application. • https://me.sap.com/notes/3481992 • CWE-359: Exposure of Private Personal Information to an Unauthorized Actor CWE-862: Missing Authorization •

CVE-2024-41729 – Information Disclosure vulnerability in the SAP NetWeaver BW (BEx Analyzer)
https://notcve.org/view.php?id=CVE-2024-41729
10 Sep 2024 — Due to missing authorization checks, SAP BEx Analyzer allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation the attacker can enumerate information causing a limited impact on confidentiality of the application. • https://me.sap.com/notes/3481588 • CWE-359: Exposure of Private Personal Information to an Unauthorized Actor CWE-862: Missing Authorization •

CVE-2024-37068 – IBM Maximo Application Suite information disclosure
https://notcve.org/view.php?id=CVE-2024-37068
07 Sep 2024 — IBM Maximo Application Suite - Manage Component 8.10, 8.11, and 9.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM Maximo Application Suite - Manage Component 8.10, 8.11, and 9.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information using man in the middle techniques. • https://exchange.xforce.ibmcloud.com/vulnerabilities/292799 • CWE-327: Use of a Broken or Risky Cryptographic Algorithm •

CVE-2024-1744 – Information Disclosure in Ariva Computer's Accord ORS
https://notcve.org/view.php?id=CVE-2024-1744
06 Sep 2024 — Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ariva Computer Accord ORS allows Retrieve Embedded Sensitive Data.This issue affects Accord ORS: before 7.3.2.1. • https://www.usom.gov.tr/bildirim/tr-24-1408 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2024-39585
https://notcve.org/view.php?id=CVE-2024-39585
06 Sep 2024 — A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Client-side request forgery and Information disclosure. • https://www.dell.com/support/kbdoc/en-us/000228357/dsa-2024-377-security-update-for-dell-networking-os10-vulnerability • CWE-259: Use of Hard-coded Password •

CVE-2024-44408
https://notcve.org/view.php?id=CVE-2024-44408
06 Sep 2024 — D-Link DIR-823G v1.0.2B05_20181207 is vulnerable to Information Disclosure. • https://github.com/lonelylonglong/openfile-/blob/main/DIR-823G.md/DIR-823G.md • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2024-45096 – IBM Aspera Faspex information disclosure
https://notcve.org/view.php?id=CVE-2024-45096
05 Sep 2024 — IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user with access to the package to obtain sensitive information through a directory listing. • https://www.ibm.com/support/pages/node/7167255 • CWE-548: Exposure of Information Through Directory Listing •