Weaknesses of type CWE-497

403 results

Divulgação de Informações Sensíveis

A aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, dados pessoais) através de canais inseguros ou em contextos onde não deveria — logs, mensagens de erro, cache, memória ou tráfego de rede desencriptado. O risco é um atacante interceptar ou acessar esses dados e comprometer contas, sistemas ou privacidade.

Example

Uma API retorna a senha do usuário em texto plano dentro de um JSON de resposta de erro; um servidor expõe tokens de autenticação em arquivos de log acessíveis publicamente; uma página web carrega chaves de API dentro de variáveis JavaScript visíveis no código-fonte.

How to mitigate

Nunca exponha dados sensíveis em logs, mensagens de erro visíveis ao usuário ou código cliente. Criptografe dados em trânsito (HTTPS/TLS), use variáveis de ambiente ou vaults para armazenar credenciais, e revise regularmente o que é registrado ou retornado em respostas. Implemente redação de dados sensíveis (masking) em logs e erros.

CVE-2025-46718LOWsudo-rs Allows Low Privilege Users to Enumerate Privileges of OthersEPSS 0.3%CVE-2023-0005MEDIUMPAN-OS: Exposure of Sensitive Information VulnerabilityEPSS 0.3%CVE-2022-4968MEDIUMnetplan leaks the private key of wireguard to local users. Versions after 1.0 are not affected.EPSS 0.3%CVE-2025-53031MEDIUMVulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (comEPSS 0.3%CVE-2026-66840HIGHXING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sensitive system informaEPSS 0.3%CVE-2025-15623CRITICALSparx Pro Cloud Server reveals sensitive information to an unauthenticated userEPSS 0.3%CVE-2025-2667LOWIBM Sterling B2B Integrator information disclosureEPSS 0.3%CVE-2025-68551MEDIUMWordPress VPSUForm plugin <= 3.2.24 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-52616MEDIUMHCL Unica 12.1.10 is affected by an exposure of sensitive informationEPSS 0.3%CVE-2026-44749MEDIUMInformation Disclosure vulnerability in SAP GatewayEPSS 0.3%CVE-2025-43024MEDIUMHP ThinPro 8.1 SP8 Security UpdatesEPSS 0.3%CVE-2025-4614MEDIUMPAN-OS: Session Token Disclosure VulnerabilityEPSS 0.3%CVE-2025-63013MEDIUMWordPress WP Hotel Booking plugin <= 2.2.7 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-67621MEDIUMWordPress Eight Day Week Print Workflow plugin <= 1.2.5 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2023-50180MEDIUMAn exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiADC version 7.4.1 and below, vEPSS 0.3%CVE-2025-67948MEDIUMWordPress SendPulse Email Marketing Newsletter plugin <= 2.2.1 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-68576MEDIUMWordPress Virusdie plugin <= 1.1.6 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-66056MEDIUMWordPress Uncanny Automator plugin < 6.10.0 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2024-58375HIGHOpenTofu before 1.8.3 Secret Variable Leaking via Static EvaluationEPSS 0.3%CVE-2025-63070MEDIUMWordPress Download Manager plugin <= 3.3.32 - Sensitive Data Exposure vulnerabilityEPSS 0.3%