Weaknesses of type CWE-209

427 results

Exposição de Informações Sensíveis em Mensagens de Erro

A aplicação retorna mensagens de erro que revelam detalhes internos do sistema — como caminhos de arquivo, nomes de banco de dados, versões de software ou stack traces — para usuários não autorizados. Um atacante usa essas informações para mapear a infraestrutura e planejar exploits direcionados.

Example

Um formulário de login mostra 'Erro SQL: usuário não encontrado em tabela users_prod' ao invés de 'Credenciais inválidas'. O atacante descobre o nome exato da tabela e começa testes de SQL injection. Ou um erro de exceção expõe '/var/www/html/config.php:42', revelando a estrutura do servidor.

How to mitigate

Exiba mensagens de erro genéricas ao usuário final ('Operação não permitida'), e registre os detalhes técnicos apenas em logs internos do servidor. Desabilite stack traces e debug info em produção, use tratamento centralizado de exceções e valide/sanitize todo output antes de devolvê-lo ao cliente.

CVE-2025-52023MEDIUMA vulnerability in the PHP backend of gemscms.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to trigger detailed erroEPSS 0.5%CVE-2025-52022MEDIUMA vulnerability in the PHP backend of gemsloyalty.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to trigger detailed EPSS 0.5%CVE-2022-4870MEDIUMIn affected versions of Octopus Deploy it is possible to discover network details via error messageEPSS 0.4%CVE-2024-35119MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.4%CVE-2024-8571MEDIUMerjemin roll_cms views.py information exposureEPSS 0.4%CVE-2023-42475MEDIUMInformation Disclosure Vulnerability in Statutory ReportingEPSS 0.4%CVE-2024-39458LOWWhen Jenkins Structs Plugin 337.v1b_04ea_4df7c8 and earlier fails to configure a build step, it logs a warning message containing diagnosticEPSS 0.4%CVE-2023-0833MEDIUMRed hat a-mq streams: component version with information disclosure flawEPSS 0.4%CVE-2022-4770MEDIUMHitachi Vantara Pentaho Business Analytics Server - Generation of Error Message Containing Sensitive Information EPSS 0.4%CVE-2022-4769MEDIUMHitachi Vantara Pentaho Business Analytics Server - Generation of Error Message Containing Sensitive Information EPSS 0.4%CVE-2025-4166MEDIUMVault May Include Sensitive Data in Error Logs When Using the KV v2 PluginEPSS 0.4%CVE-2024-45658LOWIBM Security Verify Access information disclosureEPSS 0.4%CVE-2023-23474LOWIBM Cognos Controller information disclosureEPSS 0.4%CVE-2022-0563MEDIUMA flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" envirEPSS 0.4%CVE-2024-52043MEDIUMUser enumeration in HubHubEPSS 0.4%CVE-2026-28786MEDIUMOpen WebUI vulnerable to Path Traversal in `POST /api/v1/audio/transcriptions`EPSS 0.4%CVE-2025-68110CRITICALChurchCRM discloses database information on error messageEPSS 0.4%CVE-2024-39751MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.4%CVE-2026-22646MEDIUMCertain error messages returned by the application expose internal system details that should not be visible to end users, providing attackeEPSS 0.4%CVE-2024-13540MEDIUMWooODT Lite – Delivery & pickup date time location for WooCommerce <= 2.5.1 - Unauthenticated Full Path DsiclosureEPSS 0.4%