Weaknesses of type CWE-209

427 results

Exposição de Informações Sensíveis em Mensagens de Erro

A aplicação retorna mensagens de erro que revelam detalhes internos do sistema — como caminhos de arquivo, nomes de banco de dados, versões de software ou stack traces — para usuários não autorizados. Um atacante usa essas informações para mapear a infraestrutura e planejar exploits direcionados.

Example

Um formulário de login mostra 'Erro SQL: usuário não encontrado em tabela users_prod' ao invés de 'Credenciais inválidas'. O atacante descobre o nome exato da tabela e começa testes de SQL injection. Ou um erro de exceção expõe '/var/www/html/config.php:42', revelando a estrutura do servidor.

How to mitigate

Exiba mensagens de erro genéricas ao usuário final ('Operação não permitida'), e registre os detalhes técnicos apenas em logs internos do servidor. Desabilite stack traces e debug info em produção, use tratamento centralizado de exceções e valide/sanitize todo output antes de devolvê-lo ao cliente.

CVE-2022-2508MEDIUMIn affected versions of Octopus Server it is possible to reveal the existence of resources in a space that the user does not have access to EPSS 0.5%CVE-2024-45817HIGHx86: Deadlock in vlapic_error()EPSS 0.5%CVE-2023-33181MEDIUMSensitive Information Disclosure abusing Stack Trace in Xibo CMSEPSS 0.5%CVE-2024-35156MEDIUMIBM MQ information disclosureEPSS 0.5%CVE-2022-43891LOWIBM Security Verify Privilege information disclosureEPSS 0.5%CVE-2022-40292MEDIUMUnauthenticated username enumeration in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC.EPSS 0.5%CVE-2024-13535MEDIUMActionwear products sync <= 2.3.2 - Unauthenticated Full Patch DisclosureEPSS 0.5%CVE-2023-27860MEDIUMIBM Maximo Asset Management information disclosureEPSS 0.5%CVE-2023-6839MEDIUMDue to improper error handling, a REST API resource could expose a server side error containing an internal WSO2 specific package name in thEPSS 0.5%CVE-2023-37489MEDIUMInformation Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Version Management System)EPSS 0.5%CVE-2024-31844MEDIUMAn issue was discovered in Italtel Embrace 1.6.4. The server does not properly handle application errors. In some cases, this leads to a disEPSS 0.5%CVE-2025-20150MEDIUMCisco Nexus Dashboard Username Enumeration VulnerabilityEPSS 0.5%CVE-2026-53906MEDIUMPath Disclosure and Path Traversal in MCOEPSS 0.5%CVE-2025-24552MEDIUMWordPress Paytium plugin <= 4.4.11 - Full Path Disclosure (FPD) vulnerabilityEPSS 0.5%CVE-2022-32756LOWIBM Security Verify Directory information disclosureEPSS 0.5%CVE-2025-32238MEDIUMWordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.5.5 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2026-40245HIGHFree5GC: UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authenticationEPSS 0.5%CVE-2024-28285CRITICALA Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reEPSS 0.5%CVE-2024-35232LOWgithub.com/huandu/facebook may expose access_token in error messageEPSS 0.5%CVE-2026-66306MEDIUMSkype for Business Information Disclosure VulnerabilityEPSS 0.5%