Weaknesses of type CWE-209

427 results

Exposição de Informações Sensíveis em Mensagens de Erro

A aplicação retorna mensagens de erro que revelam detalhes internos do sistema — como caminhos de arquivo, nomes de banco de dados, versões de software ou stack traces — para usuários não autorizados. Um atacante usa essas informações para mapear a infraestrutura e planejar exploits direcionados.

Example

Um formulário de login mostra 'Erro SQL: usuário não encontrado em tabela users_prod' ao invés de 'Credenciais inválidas'. O atacante descobre o nome exato da tabela e começa testes de SQL injection. Ou um erro de exceção expõe '/var/www/html/config.php:42', revelando a estrutura do servidor.

How to mitigate

Exiba mensagens de erro genéricas ao usuário final ('Operação não permitida'), e registre os detalhes técnicos apenas em logs internos do servidor. Desabilite stack traces e debug info em produção, use tratamento centralizado de exceções e valide/sanitize todo output antes de devolvê-lo ao cliente.

CVE-2025-65995MEDIUMApache Airflow: Disclosure of secrets to UI via kwargsEPSS 0.8%CVE-2015-10012LOWsumocoders FrameworkUserBundle login.html.twig information exposureEPSS 0.8%CVE-2023-23837HIGHNo Exception Handling Vulnerability: Database Performance Analyzer (DPA) 2023.1EPSS 0.8%CVE-2023-31048MEDIUMThe OPC UA .NET Standard Reference Server before 1.4.371.86. places sensitive information into an error message that may be seen remotely.EPSS 0.8%CVE-2021-33711—A vulnerability has been identified in Teamcenter Active Workspace V4 (All versions < V4.3.9), Teamcenter Active Workspace V5.0 (All versionEPSS 0.8%CVE-2022-22363MEDIUMIBM Cognos Controller information disclosureEPSS 0.8%CVE-2021-32775HIGHAny user can see any fields (including mailbox password) with GroupBy DashletEPSS 0.8%CVE-2022-31229CRITICALDell PowerScale OneFS, 8.2.x through 9.3.0.x, contain an error message with sensitive information. An administrator could potentially exploiEPSS 0.8%CVE-2020-1717—A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.EPSS 0.8%CVE-2023-29193HIGHSpiceDB binding metrics port to untrusted networks and can leak command-line flagsEPSS 0.8%CVE-2021-31339—A vulnerability has been identified in Mendix Excel Importer Module (All versions < V9.0.3). Uploading a manipulated XML File results in an EPSS 0.8%CVE-2022-22760MEDIUMWhen importing resources using Web Workers, error messages would distinguish the difference between <code>application/javascript</code> respEPSS 0.8%CVE-2023-26052LOWSaleor is vulnerable to unauthenticated information disclosure via Python exceptionsEPSS 0.8%CVE-2023-47703MEDIUMIBM Security Guardium Key Lifecycle Manager information disclosureEPSS 0.8%CVE-2018-19947MEDIUMThe vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vulnerability could disEPSS 0.8%CVE-2019-16768LOWInternal exception message exposure for login action in SyliusEPSS 0.7%CVE-2020-5026MEDIUMIBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.7 could allow a remote attacker to obtain sensitEPSS 0.7%CVE-2023-33835MEDIUMIBM Security Verify Information Queue information disclosureEPSS 0.7%CVE-2018-17891—Carestream Vue RIS, RIS Client Builds: Version 11.2 and prior running on a Windows 8.1 machine with IIS/7.5. When contacting a Carestream seEPSS 0.7%CVE-2021-31341—Uploading a table mapping using a manipulated XML file results in an exception that could expose information about the application-server anEPSS 0.7%