Weaknesses of type CWE-209

429 results

Exposição de Informações Sensíveis em Mensagens de Erro

A aplicação retorna mensagens de erro que revelam detalhes internos do sistema — como caminhos de arquivo, nomes de banco de dados, versões de software ou stack traces — para usuários não autorizados. Um atacante usa essas informações para mapear a infraestrutura e planejar exploits direcionados.

Example

Um formulário de login mostra 'Erro SQL: usuário não encontrado em tabela users_prod' ao invés de 'Credenciais inválidas'. O atacante descobre o nome exato da tabela e começa testes de SQL injection. Ou um erro de exceção expõe '/var/www/html/config.php:42', revelando a estrutura do servidor.

How to mitigate

Exiba mensagens de erro genéricas ao usuário final ('Operação não permitida'), e registre os detalhes técnicos apenas em logs internos do servidor. Desabilite stack traces e debug info em produção, use tratamento centralizado de exceções e valide/sanitize todo output antes de devolvê-lo ao cliente.

CVE-2025-26333MEDIUMDell BSAFE Crypto-J generates an error message that includes sensitive information about its environment and associated data. A remote attacEPSS 0.3%CVE-2026-59271MEDIUMAdmin password disclosed in BrokerNotAliveException messageEPSS 0.3%CVE-2026-42459HIGHfree5GC: Improper Input Validation and Generation of Error Message Containing Sensitive Information in github.com/free5gc/udmEPSS 0.3%CVE-2026-11873MEDIUMPki-core: dogtag-pki: empty request to dogtag /ca/rest/certrequests causes http 500, java exception, and stacktrace disclosureEPSS 0.3%CVE-2026-33192HIGHfree5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions requesEPSS 0.3%CVE-2026-66008MEDIUMParse Server 9.0.0 Information Disclosure via GraphQL Error MessagesEPSS 0.3%CVE-2026-13182HIGHRadAsyncUpload Client-State Decrypt-vs-Parse Oracle Vulnerability in Telerik UI for ASP.NET AJAXEPSS 0.3%CVE-2024-56342MEDIUMIBM Verify Identity Access Digital Credentials information disclosureEPSS 0.3%CVE-2026-4633LOWKeycloak: keycloak: user enumeration via differential error messagesEPSS 0.3%CVE-2023-50348LOWImproper Error Handling affects DRYiCE MyXalyticsEPSS 0.3%CVE-2024-30141MEDIUMHCL BigFix Compliance is vulnerable to the generation of error messages containing sensitive informationEPSS 0.3%CVE-2025-15526MEDIUMFancy Product Designer | WooCommerce WordPress <= 6.4.8 - Unauthenticated Full Path Disclosure via 'pdf' ParameterEPSS 0.3%CVE-2026-77950MEDIUMRPC error handler fails open in AshTypescript, disclosing unredacted errorsEPSS 0.3%CVE-2026-82733MEDIUMRoute handler return value echoed into AshTypescript error responseEPSS 0.3%CVE-2025-1395HIGHSensitive Data Exposure in CoDeriApp's HeyGarsonEPSS 0.3%CVE-2025-36348MEDIUMThe Dashboard of IBM Sterling B2B Integrator and IBM Sterling File Gateway is Vulnerable to Information DisclosureEPSS 0.3%CVE-2022-50686MEDIUMKentico Xperience <= 12.0 Portal Engine Form Control Information DisclosureEPSS 0.3%CVE-2026-24130LOWMoonraker with LDAP Enabled Allows Malicious Search Filter InjectionEPSS 0.3%CVE-2024-5250LOWOverly Verbose Errors in SAML IntegrationEPSS 0.3%CVE-2025-20002MEDIUMGMOD Apollo Generation of Error Message Containing Sensitive InformationEPSS 0.3%