Description
Certain error messages returned by the application expose internal system details that should not be visible to end users, providing attackers with valuable reconnaissance information (like file paths, database errors, or software versions) that can be used to map the application's internal structure and discover other, more critical vulnerabilities.
Published: 2026-01-15
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Users are strongly recommended to upgrade to the latest release of Incoming Goods Suite (>= 1.2.1).

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 29 Jan 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Sick
Sick incoming Goods Suite
CPEs cpe:2.3:a:sick:incoming_goods_suite:*:*:*:*:*:*:*:*
Vendors & Products Sick
Sick incoming Goods Suite

Mon, 19 Jan 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Sick Ag
Sick Ag incoming Goods Suite
Vendors & Products Sick Ag
Sick Ag incoming Goods Suite

Thu, 15 Jan 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 Jan 2026 13:45:00 +0000

Type Values Removed Values Added
Description Certain error messages returned by the application expose internal system details that should not be visible to end users, providing attackers with valuable reconnaissance information (like file paths, database errors, or software versions) that can be used to map the application's internal structure and discover other, more critical vulnerabilities.
Weaknesses CWE-209
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Sick Incoming Goods Suite
Sick Ag Incoming Goods Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: SICK AG

Published:

Updated: 2026-01-15T14:35:40.263Z

Reserved: 2026-01-08T09:59:06.199Z

Link: CVE-2026-22646

cve-icon Vulnrichment

Updated: 2026-01-15T14:35:33.792Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-15T14:16:28.430

Modified: 2026-01-29T16:18:21.980

Link: CVE-2026-22646

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-19T09:20:43Z

Weaknesses