Common Weakness Enumeration

    CWE Definition / CWE-497

    CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere

    The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

    Published:19 Jul 2006
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-200: Exposure of Sensitive Information to an Unauthorized Actor