Weaknesses of type CWE-209

433 results

Exposição de Informações Sensíveis em Mensagens de Erro

A aplicação retorna mensagens de erro que revelam detalhes internos do sistema — como caminhos de arquivo, nomes de banco de dados, versões de software ou stack traces — para usuários não autorizados. Um atacante usa essas informações para mapear a infraestrutura e planejar exploits direcionados.

Example

Um formulário de login mostra 'Erro SQL: usuário não encontrado em tabela users_prod' ao invés de 'Credenciais inválidas'. O atacante descobre o nome exato da tabela e começa testes de SQL injection. Ou um erro de exceção expõe '/var/www/html/config.php:42', revelando a estrutura do servidor.

How to mitigate

Exiba mensagens de erro genéricas ao usuário final ('Operação não permitida'), e registre os detalhes técnicos apenas em logs internos do servidor. Desabilite stack traces e debug info em produção, use tratamento centralizado de exceções e valide/sanitize todo output antes de devolvê-lo ao cliente.

CVE-2024-41984LOWA vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >=EPSS 0.2%CVE-2025-5731MEDIUMInfinispan: credential leakage in infinispan cliEPSS 0.2%CVE-2026-56537LOWHCL Connections is vulnerable to information disclosureEPSS 0.2%CVE-2026-24511MEDIUMDell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.0, contains a generation of error message contEPSS 0.2%CVE-2025-55250LOWHCL AION is affected by a Technical Error Disclosure vulnerabilityEPSS 0.2%CVE-2025-52611LOWHCL iControl was affected by Unhandled Exception - Stack Trace Disclosure vulnerabilityEPSS 0.2%CVE-2024-56812LOWIBM EntireX information disclosureEPSS 0.1%CVE-2025-59177MEDIUMGeneration of Error Message Containing Sensitive Information VulnerabilityEPSS 0.1%CVE-2024-56467LOWIBM EntireX information disclosureEPSS 0.1%CVE-2024-56494LOWIBM EntireX information disclosureEPSS 0.1%CVE-2024-56495LOWIBM EntireX information disclosureEPSS 0.1%CVE-2024-56493LOWIBM EntireX information disclosureEPSS 0.1%CVE-2024-56811LOWIBM EntireX information disclosureEPSS 0.1%CVE-2024-56810LOWIBM EntireX information disclosureEPSS 0.1%CVE-2024-56496LOWIBM EntireX information disclosureEPSS 0.1%CVE-2025-40760MEDIUMA vulnerability has been identified in Altair Grid Engine (All versions < V2026.0.0). Affected products do not properly handle error messageEPSS 0.1%CVE-2026-82739LOWAsh.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic mismatch errorEPSS 0.1%CVE-2026-29110LOWCryptomator: Leaking of cleartext paths into log file in non-debug modeEPSS 0.1%CVE-2026-7860LOWPossible information disclosure of environment variables in Vaadin Build Plugins via Failed Frontend BuildEPSS 0.1%CVE-2022-20525LOWIn enforceVisualVoicemailPackage of PhoneInterfaceManager.java, there is a possible leak of visual voicemail package name due to a permissioEPSS 0.1%