← Vulnerability feed

Vulnerability record · CVE-2025-58581 · published 6 October 2025

CVE-2025-58581: Sick enterprise analytics information exposure vulnerability

Sick · Enterprise Analytics

When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker can thus obtain information about the technology used and the structure of the application.

4.3 CVSS 3.1 Medium EPSS 0.33% · top 76.0% CWE-200 · Information exposure
4.3CVSS 3.1 base score
0.33%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker can thus obtain information about the technology used and the structure of the application.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-58581 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-58587Sick baggage analytics improper restriction of authentication attempts vulnerabilityThe application does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it possib…EPSS 0.49%7.5CVE-2025-58584Sick baggage analytics vulnerabilityIn the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such…EPSS 0.39%7.5CVE-2025-58582Sick enterprise analytics allocation without limits vulnerabilityIf a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is not validated and it’s possi…EPSS 0.55%7.5CVE-2025-49184Sick baggage analytics information exposure vulnerabilityA remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of configuration settings of the pro…EPSS 0.49%5.3CVE-2025-58586Sick baggage analytics vulnerabilityFor failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a n…EPSS 0.36%5.3CVE-2025-58579Sick baggage analytics vulnerabilityDue to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making the application vulnerable for…EPSS 0.40%5.3CVE-2025-58580Sick enterprise analytics vulnerabilityAn API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation of the input data, an attacker can create …EPSS 0.37%5.3CVE-2025-58583Sick enterprise analytics vulnerabilityThe application provides access to a login protected H2 database for caching purposes. The username is prefilled.EPSS 0.36%

Source: NIST National Vulnerability Database (record CVE-2025-58581), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.