Fallos del tipo CWE-200

4980 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2022-43539MEDIUM A vulnerability exists in the ClearPass Policy Manager cluster communications that allow for an attacker in a privileged network position tEPSS 0.3%CVE-2026-16373HIGHInformation disclosure in the Privacy component in Firefox for AndroidEPSS 0.3%CVE-2026-35145LOWHCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability.EPSS 0.3%CVE-2023-47298MEDIUMAn issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obtain informaEPSS 0.3%CVE-2025-64179MEDIUMlakeFS: Unauthenticated access to API usage metricsEPSS 0.3%CVE-2026-61294MEDIUMVulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Calendar Synchronizations). SupportEPSS 0.3%CVE-2026-61266MEDIUMVulnerability in the Oracle Supply Chain Globalization product of Oracle E-Business Suite (component: Copy Inventory Organization). SupportEPSS 0.3%CVE-2026-62528MEDIUMVulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Install). Supported versions that arEPSS 0.3%CVE-2025-13973MEDIUMStickEasy Protected Contact Form <= 1.0.1 - Unauthenticated Information DisclosureEPSS 0.3%CVE-2020-10698—A flaw was found in Ansible Tower when running jobs. This flaw allows an attacker to access the stdout of the executed jobs which are run frEPSS 0.3%CVE-2026-62527MEDIUMVulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Import And Export). Supported versions that EPSS 0.3%CVE-2022-34674MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where a helper function maps more physical paEPSS 0.3%CVE-2025-63579HIGHUnauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that enEPSS 0.3%CVE-2026-4202LOWBroken Access Control in extension "Redirect Tab"EPSS 0.3%CVE-2025-9987MEDIUMBroadstreet <= 1.53.1 - Authenticated (Subscriber+) Information DisclosureEPSS 0.3%CVE-2026-61123MEDIUMVulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affeEPSS 0.3%CVE-2026-49288MEDIUMStatamic CMS missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resourcesEPSS 0.3%CVE-2026-61103MEDIUMVulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version tEPSS 0.3%CVE-2026-86418LOWMISP Dashboard Organisation Picker Exposes Hidden Organisation Metadata to Unauthorized UsersEPSS 0.3%CVE-2026-42392MEDIUMAn attacker that has valid credentials can send an invalid IMAP URLFETCH command, which causes uninitialized memory to be included in the erEPSS 0.3%