Weaknesses of type CWE-209

432 results

Exposição de Informações Sensíveis em Mensagens de Erro

A aplicação retorna mensagens de erro que revelam detalhes internos do sistema — como caminhos de arquivo, nomes de banco de dados, versões de software ou stack traces — para usuários não autorizados. Um atacante usa essas informações para mapear a infraestrutura e planejar exploits direcionados.

Example

Um formulário de login mostra 'Erro SQL: usuário não encontrado em tabela users_prod' ao invés de 'Credenciais inválidas'. O atacante descobre o nome exato da tabela e começa testes de SQL injection. Ou um erro de exceção expõe '/var/www/html/config.php:42', revelando a estrutura do servidor.

How to mitigate

Exiba mensagens de erro genéricas ao usuário final ('Operação não permitida'), e registre os detalhes técnicos apenas em logs internos do servidor. Desabilite stack traces e debug info em produção, use tratamento centralizado de exceções e valide/sanitize todo output antes de devolvê-lo ao cliente.

CVE-2025-46746MEDIUMError Message Contains Sensitive InformationEPSS 0.3%CVE-2026-77076HIGHn8n before 1.123.69 Credential Leak via GraphQL Node ErrorEPSS 0.3%CVE-2025-14243MEDIUMMirror-registry: openshift mirror registry: user enumeration via authentication error messagesEPSS 0.3%CVE-2025-9229MEDIUMInformation Disclosure in MiR robots and MiR fleet through verbose error pagesEPSS 0.3%CVE-2025-23185MEDIUMInformation Disclosure in SAP Business Objects Business Intelligence PlatformEPSS 0.3%CVE-2025-9122MEDIUMHitachi Vantara Pentaho Business Analytics Server - Generation of Error Message Containing Sensitive InformationEPSS 0.3%CVE-2026-2484MEDIUMIBM InfoSphere Information Server Information DisclosureEPSS 0.3%CVE-2026-75760HIGHAshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing errorEPSS 0.3%CVE-2026-33065MEDIUMfree5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions requestEPSS 0.3%CVE-2025-69208LOWfree5GC UDR's NEF incorrectly returns 500 for missing PFD data (UDR 404) in Nnef_PfdManagement GET requestEPSS 0.3%CVE-2026-21783MEDIUMHCL Traveler is affected by sensitive information disclosureEPSS 0.3%CVE-2026-27643MEDIUMfree5GC has improper error handling in NEF with information exposureEPSS 0.3%CVE-2024-52896MEDIUMIBM MQ information disclosureEPSS 0.3%CVE-2025-52619MEDIUMHCL BigFix SaaS Authentication Service is affected by a sensitive information disclosureEPSS 0.3%CVE-2025-36090MEDIUMIBM Analytics Content Hub information disclosureEPSS 0.3%CVE-2026-82580MEDIUMAshAi echoes raw tool exception messages into the conversation, disclosing internal detailsEPSS 0.3%CVE-2026-82727LOWAshPhoenix Form.Auto leaks submitted params in an unknown _union_type error messageEPSS 0.3%CVE-2026-41935HIGHVvveb < 1.0.8.3 Uncontrolled Recursion Denial of ServiceEPSS 0.3%CVE-2026-47622MEDIUMNVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that contain sensitive inforEPSS 0.3%CVE-2026-66009MEDIUMParse Server 9.0.0 Information Disclosure via GraphQL Error MessagesEPSS 0.3%