Weaknesses of type CWE-209

427 results

Exposição de Informações Sensíveis em Mensagens de Erro

A aplicação retorna mensagens de erro que revelam detalhes internos do sistema — como caminhos de arquivo, nomes de banco de dados, versões de software ou stack traces — para usuários não autorizados. Um atacante usa essas informações para mapear a infraestrutura e planejar exploits direcionados.

Example

Um formulário de login mostra 'Erro SQL: usuário não encontrado em tabela users_prod' ao invés de 'Credenciais inválidas'. O atacante descobre o nome exato da tabela e começa testes de SQL injection. Ou um erro de exceção expõe '/var/www/html/config.php:42', revelando a estrutura do servidor.

How to mitigate

Exiba mensagens de erro genéricas ao usuário final ('Operação não permitida'), e registre os detalhes técnicos apenas em logs internos do servidor. Desabilite stack traces e debug info em produção, use tratamento centralizado de exceções e valide/sanitize todo output antes de devolvê-lo ao cliente.

CVE-2024-54141HIGHphpMyFAQ Generates an Error Message Containing Sensitive Information if database server is not availableEPSS 0.5%CVE-2026-1175MEDIUMbirkir prime GraphQL Directive graphql information exposureEPSS 0.5%CVE-2022-2760MEDIUMIn affected versions of Octopus Deploy it is possible to reveal the Space ID of spaces that the user does not have access to view in an erroEPSS 0.5%CVE-2021-20455LOWIBM Cognos Controller information disclosureEPSS 0.5%CVE-2023-25687MEDIUMIBM Security Key Lifecycle Manager information disclosureEPSS 0.5%CVE-2024-30614MEDIUMAn issue in Ametys CMS v4.5.0 and before allows attackers to obtain sensitive information via exposed resources to the error scope.EPSS 0.5%CVE-2026-43630MEDIUMllama.cpp b5702–b7653 Out-of-Bounds Read Information DisclosureEPSS 0.5%CVE-2025-23216MEDIUMArgo CD does not scrub secret values from patch errorsEPSS 0.5%CVE-2026-34045HIGHPodman Desktop WebView Server ExposedEPSS 0.5%CVE-2025-8548MEDIUMatjiu pybbs Registered Email SettingsApiController.java sendEmailCode information exposureEPSS 0.5%CVE-2026-64627MEDIUMParse Server 9.0.0 Schema Disclosure via GraphQL Variable CoercionEPSS 0.5%CVE-2022-46675MEDIUM Wyse Management Suite Repository 3.8 and below contain an information disclosure vulnerability. A unauthenticated attacker could potentiallEPSS 0.5%CVE-2026-69684MEDIUMWindows Error Reporting Information Disclosure VulnerabilityEPSS 0.5%CVE-2020-16121LOWPackageKit error messages leak presence and mimetype of files to unprivileged usersEPSS 0.5%CVE-2024-49818MEDIUMIBM Security Guardium Key Lifecycle Manager information disclosureEPSS 0.5%CVE-2026-68886MEDIUMWindows Network Connection Broker Information Disclosure VulnerabilityEPSS 0.5%CVE-2023-47728MEDIUMIBM QRadar Suite Software information disclosureEPSS 0.5%CVE-2024-5435MEDIUMGeneration of Error Message Containing Sensitive Information in GitLabEPSS 0.5%CVE-2023-26272MEDIUMIBM Security Guardium Data Encryption information disclosureEPSS 0.5%CVE-2025-59872MEDIUMHCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability,EPSS 0.5%