Weaknesses of type CWE-209

433 results

Exposição de Informações Sensíveis em Mensagens de Erro

A aplicação retorna mensagens de erro que revelam detalhes internos do sistema — como caminhos de arquivo, nomes de banco de dados, versões de software ou stack traces — para usuários não autorizados. Um atacante usa essas informações para mapear a infraestrutura e planejar exploits direcionados.

Example

Um formulário de login mostra 'Erro SQL: usuário não encontrado em tabela users_prod' ao invés de 'Credenciais inválidas'. O atacante descobre o nome exato da tabela e começa testes de SQL injection. Ou um erro de exceção expõe '/var/www/html/config.php:42', revelando a estrutura do servidor.

How to mitigate

Exiba mensagens de erro genéricas ao usuário final ('Operação não permitida'), e registre os detalhes técnicos apenas em logs internos do servidor. Desabilite stack traces e debug info em produção, use tratamento centralizado de exceções e valide/sanitize todo output antes de devolvê-lo ao cliente.

CVE-2024-3454LOWIn-Fabric Matter Cluster Attribute DisclosureEPSS 0.2%CVE-2026-8173MEDIUMInformation Disclosure via 'Copy learned MAC Addresses' FunctionEPSS 0.2%CVE-2026-40969LOWSpring gRPC AuthenticationException message reflected to remote clientEPSS 0.2%CVE-2026-4994MEDIUMwandb OpenUI APIStatusError server.py generic_exception_handler information exposureEPSS 0.2%CVE-2026-33333LOWCombodo iTop: Information disclosure in ajax.render.phpEPSS 0.2%CVE-2026-41730MEDIUMSpring Data REST exposes persistence-layer internals in error responsesEPSS 0.2%CVE-2026-56568LOWHCL iControl is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2024-41983MEDIUMA vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >=EPSS 0.2%CVE-2026-22052MEDIUMONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could alEPSS 0.2%CVE-2025-0941MEDIUMMET ONE 3400+ Potential Credential ExposureEPSS 0.2%CVE-2023-40725MEDIUMA vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application returns inconsistent error messages EPSS 0.2%CVE-2024-6613MEDIUMIncorrect listing of stack framesEPSS 0.2%CVE-2023-28514MEDIUMIBM MQ information disclosureEPSS 0.2%CVE-2022-35640MEDIUMIBM Sterling Partner Engagement Manager information disclosureEPSS 0.2%CVE-2024-52898MEDIUMIBM MQ information disclosureEPSS 0.2%CVE-2026-69247HIGHcryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timingEPSS 0.2%CVE-2026-56571LOWHCL iControl is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2022-34881LOWInformation Exposure Vulnerability in JP1/Automatic OperationEPSS 0.2%CVE-2025-52606MEDIUMHCL iControl was affected by Weak Input Validation vulnerability. .EPSS 0.2%CVE-2025-59853LOWHCL DFXAnalytics is affected by an Improper Error Handling vulnerabilityEPSS 0.2%