MEDIUM🇵🇱 Wersja polska

CVE-2025-58581

CVSS 4.3v3.1pub. 2025-10-06upd. 2026-01-27

When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker can thus obtain information about the technology used and the structure of the application.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
  • Sick Enterprise Analytics

    APP
    Sick
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-49184HIGH7.5same product

A remote unauthorized attacker may gather sensitive information of the application, due to missing authorizati...

CVE-2025-58579MEDIUM5.3same product

Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint...

CVE-2025-58580MEDIUM6.5same product

An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient va...

CVE-2025-58582MEDIUM5.3same product

If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST r...

CVE-2025-58583MEDIUM5.3same product

The application provides access to a login protected H2 database for caching purposes. The username...