Fallos del tipo CWE-200

4980 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2023-45816LOWUnread bookmark reminder notifications that the user cannot access can be seenEPSS 0.3%CVE-2024-44685MEDIUMTitan SFTP and Titan MFT Server 2.0.25.2426 and earlier have a vulnerability a vulnerability where sensitive information, including passwordEPSS 0.3%CVE-2026-14049MEDIUMInappropriate implementation in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer proceEPSS 0.3%CVE-2026-105120MEDIUMOpenAM before 16.1.3 Cross-Realm Session Disclosure via Sessions REST EndpointEPSS 0.3%CVE-2020-6653LOWSensitive date stored in logcat fileEPSS 0.3%CVE-2025-24174HIGHThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app mEPSS 0.3%CVE-2026-60950LOWVulnerability in the Oracle HRMS (Ireland) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that areEPSS 0.3%CVE-2023-38296HIGHVarious software builds for the following TCL 30Z and TCL A3X devices leak the ICCID to a system property that can be accessed by any local EPSS 0.3%CVE-2021-21512HIGHDell EMC PowerProtect Cyber Recovery, version 19.7.0.1, contains an Information Disclosure vulnerability. A locally authenticated high priviEPSS 0.3%CVE-2023-36476HIGH`calamares-nixos-extensions` LUKS keyfile exposureEPSS 0.3%CVE-2026-61214LOWVulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are EPSS 0.3%CVE-2021-32007LOWMissing security header: Referrer-Policy URLEPSS 0.3%CVE-2022-0987—A flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface examines files. This issue allows a localEPSS 0.3%CVE-2025-65957HIGHCore Bot is Leaking Sensitive Credentials in Logs, Errors, and MessagesEPSS 0.3%CVE-2025-61764MEDIUMVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.3%CVE-2026-62453MEDIUMVulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affeEPSS 0.3%CVE-2025-13804MEDIUMnutzam NutzBoot Ethereum Wallet EthModule.java information disclosureEPSS 0.3%CVE-2025-24281MEDIUMThis issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive usEPSS 0.3%CVE-2025-11406MEDIUMkaifangqian kaifangqian-base SysUserController.java getAllUsers information disclosureEPSS 0.3%CVE-2026-61216MEDIUMVulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Payroll). Supported versions that are affected are 12.2.EPSS 0.3%