CWE-615: Inclusion of Sensitive Information in Source Code Comments
While adding general comments is very useful, some programmers tend to leave important data, such as: filenames related to the web application, old links or links which were not meant to be browsed by users, old code fragments, etc.
3 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-52298 — macro-pdfviewer's preview in WYSIWYG editor allows accessing any PDF document as the last author
- CVE-2026-3158 — Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway due to information disclosure
- CVE-2026-3157 — Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway due to information disclosure in mailbox UI
Recently published
- CVE-2026-3157 — Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway due to information disclosure in mailbox UI
- CVE-2026-3158 — Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway due to information disclosure
- CVE-2024-52298 — macro-pdfviewer's preview in WYSIWYG editor allows accessing any PDF document as the last author