CWE-528: Exposure of Core Dump File to an Unauthorized Control Sphere
The product generates a core dump file in a directory, archive, or other resource that is stored, transferred, or otherwise made accessible to unauthorized actors.
2 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-48928 — The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent
- CVE-2024-10403 — SFTP/FTP password could be captured in plain text in Supportsave generated from SANnav
Recently published
- CVE-2025-48928 — The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent
- CVE-2024-10403 — SFTP/FTP password could be captured in plain text in Supportsave generated from SANnav