Fallos del tipo CWE-200

5020 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2025-43201MEDIUMThis issue was addressed with improved checks. This issue is fixed in Apple Music Classical 2.3 for Android. An app may be able to unexpecteEPSS 0.1%CVE-2026-34268LOWVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: SecuritEPSS 0.1%CVE-2019-1589MEDIUMCisco Nexus 9000 Series Fabric Switches Application Centric Infrastructure Mode Unmeasured Boot VulnerabilityEPSS 0.1%CVE-2026-41960MEDIUMPermission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2026-20647MEDIUMThis issue was addressed with improved data protection. This issue is fixed in macOS Tahoe 26.3. An app may be able to access sensitive userEPSS 0.1%CVE-2026-20606HIGHThis issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macEPSS 0.1%CVE-2026-20641HIGHA privacy issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS SeqEPSS 0.1%CVE-2025-23290LOWNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a guest could get global GPU metrics which may be influencedEPSS 0.1%CVE-2025-11697HIGHStudio 5000 ® Simulation Interface Local Code ExecutionEPSS 0.1%CVE-2023-5339MEDIUMMattermost Desktop logs all keystrokes during initial run after fresh installation EPSS 0.1%CVE-2026-20623MEDIUMA permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.3. An app mayEPSS 0.1%CVE-2026-0245MEDIUMPrisma Access Agent: Information Disclosure VulnerabilitiesEPSS 0.1%CVE-2025-24090LOWA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app may be able to enumeEPSS 0.1%CVE-2026-22101MEDIUMSensitive information leak through hidden menuEPSS 0.1%CVE-2026-16973MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%CVE-2026-33448MEDIUMFormat string vulnerability in MacOS clients prior to 14.50EPSS 0.1%CVE-2024-34684LOWInformation Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Scheduling)EPSS 0.1%CVE-2024-38798MEDIUMUncleared password keystrokes in circular queue can lead to information disclosure or escalation of privilegeEPSS 0.1%CVE-2026-20612MEDIUMA privacy issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An aEPSS 0.1%CVE-2020-9089LOWThere is an information vulnerability in Huawei smartphones. A function in a module can be called without verifying the caller's access. AttEPSS 0.1%