Fallos del tipo CWE-200

4959 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-61125HIGHVulnerability in the Oracle Configure to Order product of Oracle E-Business Suite (component: Supply to Order Workbench). Supported versionEPSS 0.4%CVE-2026-87127HIGHVulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: G-Invoicing). Supported versions that are affected arEPSS 0.4%CVE-2026-34313MEDIUMVulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (comEPSS 0.4%CVE-2026-44736MEDIUMOpenProject: Relations API Filter Bypasses Visibility Scope, Leaking Cross-Project Work Package SubjectsEPSS 0.4%CVE-2026-62470MEDIUMVulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Manager Self-Service). Supported veEPSS 0.4%CVE-2026-60548HIGHVulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Supported versions thaEPSS 0.4%CVE-2023-4876HIGHExposure of Sensitive Information to an Unauthorized Actor in hamza417/inureEPSS 0.4%CVE-2026-60899MEDIUMVulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Rapid Implementation). Supported verEPSS 0.4%CVE-2026-60440HIGHVulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that EPSS 0.4%CVE-2026-60609MEDIUMVulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Communication). The supported versEPSS 0.4%CVE-2024-36986MEDIUMRisky command safeguards bypass through Search ID query in Analytics WorkspaceEPSS 0.4%CVE-2025-31225HIGHA privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.5 and iPadOS 18.5. Call history from deleted apps maEPSS 0.4%CVE-2026-61014HIGHVulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions thEPSS 0.4%CVE-2026-60835MEDIUMVulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that aEPSS 0.4%CVE-2026-34300MEDIUMVulnerability in the PeopleSoft Enterprise FIN Contracts product of Oracle PeopleSoft (component: Contracts). The supported version that iEPSS 0.4%CVE-2026-60673MEDIUMVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 8.EPSS 0.4%CVE-2026-21626CRITICALExtension - stackideas.com - Information disclosure in post custom fields in EasyDiscuss 1.0.0-5.0.15 for JoomlaEPSS 0.4%CVE-2026-72834MEDIUMfilebrowser before 2.63.19 Permission Bypass via checksumEPSS 0.4%CVE-2025-31494LOWAutoGPT allows cross-user sharing of node execution results through WebSockets APIEPSS 0.4%CVE-2026-81679HIGHOpenRemote before 1.28.0 Cross-Realm Information Disclosure via Notification APIEPSS 0.4%