A sensitive information disclosure vulnerability exists in the error handling component of ATISoluciones CIGES Application version 2.15.6 and earlier. When certain unexpected conditions trigger unhandled exceptions, the application returns detailed error messages and stack traces to the client. This may expose internal filesystem paths, SQL queries, database connection details, or environment configuration data to remote unauthenticated attackers. This issue allows information gathering and reconnaissance but does not enable direct system compromise.
History

Tue, 25 Nov 2025 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Atisoluciones
Atisoluciones ciges
Vendors & Products Atisoluciones
Atisoluciones ciges

Mon, 24 Nov 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Nov 2025 07:45:00 +0000

Type Values Removed Values Added
Description A sensitive information disclosure vulnerability exists in the error handling component of ATISoluciones CIGES Application version 2.15.6 and earlier. When certain unexpected conditions trigger unhandled exceptions, the application returns detailed error messages and stack traces to the client. This may expose internal filesystem paths, SQL queries, database connection details, or environment configuration data to remote unauthenticated attackers. This issue allows information gathering and reconnaissance but does not enable direct system compromise.
Title Improper Error Handling Leading to Sensitive Information Disclosure in CIGES ≤ 2.15.6
Weaknesses CWE-200
CWE-209
References
Metrics cvssV4_0

{'score': 2.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/S:N/AU:N/R:U/V:D/U:Clear'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ATIS

Published: 2025-11-24T07:30:49.545Z

Updated: 2025-11-24T13:47:44.911Z

Reserved: 2025-11-24T07:29:40.249Z

Link: CVE-2025-13596

cve-icon Vulnrichment

Updated: 2025-11-24T13:47:41.320Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-24T08:16:00.683

Modified: 2025-11-25T22:16:16.690

Link: CVE-2025-13596

cve-icon Redhat

No data.