Fallos del tipo CWE-200

4979 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2025-52669MEDIUMInsecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to havEPSS 0.3%CVE-2025-3851MEDIUMDownload Manager and Payment Form WordPress Plugin – WP SmartPay 1.1.0 - 2.7.13 - Authenticated (Subscriber+) Information ExposureEPSS 0.3%CVE-2022-32913LOWThe issue was addressed with additional restrictions on the observability of app states. This issue is fixed in macOS Big Sur 11.7, macOS VeEPSS 0.3%CVE-2026-60705HIGHVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that EPSS 0.3%CVE-2024-42339MEDIUMCyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.3%CVE-2024-42338MEDIUMCyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.3%CVE-2026-100671HIGHGrav before 2.0.25 Session Cookie Theft via Twig SandboxEPSS 0.3%CVE-2024-58255MEDIUMEnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.EPSS 0.3%CVE-2026-84464HIGHZammad: IDOR in External Data Source rendering exposes ticket, user, group, and organization dataEPSS 0.3%CVE-2024-45250MEDIUMZKteco – CWE 200 Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.3%CVE-2025-49824LOWconda-smithy Insecure Encryption Vulnerable to Oracle Padding AttackEPSS 0.3%CVE-2022-22506MEDIUMIBM Robotic Process Automation information disclosureEPSS 0.3%CVE-2025-31955HIGHHCL iAutomate is affected by a sensitive data exposure vulnerabilityEPSS 0.3%CVE-2021-0170MEDIUMExposure of Sensitive Information to an Unauthorized Actor in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systemsEPSS 0.3%CVE-2026-27949LOWPlane Exposes User Email (PII and part of credential) in GET ParameterEPSS 0.3%CVE-2025-46382MEDIUMCWE-200 Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.3%CVE-2025-53092MEDIUMStrapi core vulnerable to sensitive data exposure via CORS misconfigurationEPSS 0.3%CVE-2025-54786MEDIUMSuiteCRM: Legacy iCal service allows unauthenticated access to meeting dataEPSS 0.3%CVE-2026-56584LOWHCL IEM was affected with the Information disclosure nginx serverEPSS 0.3%CVE-2025-24164MEDIUMA logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An aEPSS 0.3%