Sensitive Information Exposure in ATISoluciones CIGES Application
CVE-2025-13596

2.7LOW

Key Information:

Status
Vendor
CVE Published:
24 November 2025

What is CVE-2025-13596?

A vulnerability in the ATISoluciones CIGES Application allows for sensitive information exposure through its error handling component. When the application encounters unexpected conditions and generates unhandled exceptions, it may leak detailed error messages and stack traces. These disclosures can reveal critical information such as internal filesystem paths, SQL queries, database connection details, and sensitive environment configurations to unverified external attackers. While this vulnerability facilitates information gathering and reconnaissance, it does not directly compromise system integrity.

Affected Version(s)

CIGES Linux 2.15.0 < 2.15.6

References

CVSS V4

Score:
2.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-13596 : Sensitive Information Exposure in ATISoluciones CIGES Application