Fallos del tipo CWE-200

5018 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2026-86887LOWA privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27EPSS 0.2%CVE-2024-1591LOWPrivilege Management for Windows < 24.1 Information LeakEPSS 0.2%CVE-2025-20158MEDIUMCisco Video Phone 8875 and Desk Phone 9800 Series Information Disclosure VulnerabilityEPSS 0.2%CVE-2026-24198MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability where an advanced attacker could use a race condition to leak sensitive memoryEPSS 0.2%CVE-2024-57096MEDIUMAn issue in wps office before v.19302 allows a local attacker to obtain sensitive information via a crafted file.EPSS 0.2%CVE-2025-43360MEDIUMThe issue was addressed with improved UI. This issue is fixed in iOS 26 and iPadOS 26. Password fields may be unintentionally revealed.EPSS 0.2%CVE-2024-23563LOWHCL Connections Docs is vulnerable to a sensitive information disclosureEPSS 0.2%CVE-2026-60318LOWVulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Patchset Assistant). Supported versions that arEPSS 0.2%CVE-2026-60405LOWVulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The suppoEPSS 0.2%CVE-2026-86883MEDIUMA privacy issue was addressed with improved handling of files. This issue is fixed in iOS 27 and iPadOS 27, visionOS 27. An app may be able EPSS 0.2%CVE-2026-83277HIGHVulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that isEPSS 0.2%CVE-2026-20166MEDIUMSensitive Information Disclosure in Discover Splunk Observability Cloud app for Splunk EnterpriseEPSS 0.2%CVE-2026-44276MEDIUMDell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exposure of Sensitive Information to an Unauthorized Actor vulneraEPSS 0.2%CVE-2026-84626LOWAn information disclosure issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPEPSS 0.2%CVE-2026-46406MEDIUMClaude Code: Insecure Temporary File in /copy Command Enables Response Disclosure and Symlink-Based File WriteEPSS 0.2%CVE-2026-65371LOWThis issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15EPSS 0.2%CVE-2025-31982LOWHCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directlEPSS 0.2%CVE-2026-15642LOWInsertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Server 2026.1.22.0, 2026.EPSS 0.2%CVE-2025-61679HIGHAnyquery Unauthenticated Access Vulnerability Exposes Private Integration DataEPSS 0.2%CVE-2026-49356LOWBabel: Arbitrary File Read via sourceMappingURL Comment in @babel/coreEPSS 0.2%