Fallos del tipo CWE-200

4909 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2018-1097—A flaw was found in foreman before 1.16.1. The issue allows users with limited permissions for powering oVirt/RHV hosts on and off to discovEPSS 1.7%CVE-2020-8232—An information disclosure vulnerability exists in EdgeMax EdgeSwitch firmware v1.9.0 that allowed read only users could obtain unauthorized EPSS 1.7%CVE-2024-21380HIGHMicrosoft Dynamics Business Central/NAV Information Disclosure VulnerabilityEPSS 1.7%CVE-2018-0111—A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access sensitive data about the applicatioEPSS 1.7%CVE-2025-1636MEDIUMExposure of sensitive information in My Personal Credentials password history component in Devolutions Remote Desktop Manager 2024.3.29 and EPSS 1.7%CVE-2025-1635MEDIUMExposure of sensitive information in hub data source export feature in Devolutions Remote Desktop Manager 2024.3.29 and earlier on Windows aEPSS 1.7%CVE-2018-0266—A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view sensitiveEPSS 1.7%CVE-2022-2827HIGHAMI MegaRAC User Enumeration VulnerabilityEPSS 1.7%CVE-2021-21424MEDIUMPrevent user enumeration using Guard or the new Authenticator-based SecurityEPSS 1.7%CVE-2021-41251MEDIUMPossibility to elevate privileges or get unauthorized access to dataEPSS 1.7%CVE-2019-6849—A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the diEPSS 1.7%CVE-2019-6850—A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the diEPSS 1.7%CVE-2017-12295—A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access sensitive data about the applicatioEPSS 1.7%CVE-2020-15250MEDIUMInformation disclosure in JUnit4EPSS 1.7%CVE-2022-31051MEDIUMExposure of Sensitive Information to an Unauthorized Actor in semantic-releaseEPSS 1.7%CVE-2021-34749MEDIUMMultiple Cisco Products Server Name Identification Data Exfiltration VulnerabilityEPSS 1.7%CVE-2017-16715HIGHAn Information Exposure issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version 2.6, NPort 5110 VersEPSS 1.7%CVE-2021-30169MEDIUMMERIT LILIN ENT.CO.,LTD. P2/Z2/P3/Z3 IP camera - Sensitive Data Exposure-2EPSS 1.7%CVE-2022-34692MEDIUMMicrosoft Exchange Server Information Disclosure VulnerabilityEPSS 1.7%CVE-2024-35263MEDIUMMicrosoft Dynamics 365 (On-Premises) Information Disclosure VulnerabilityEPSS 1.7%