Fallos del tipo CWE-200

5032 resultados

Exposição de Informação Sensível

A aplicação divulga dados sensíveis (senhas, tokens, dados pessoais, chaves) para usuários ou sistemas que não têm autorização para acessá-los. Isso acontece por falta de controle de acesso adequado, logging verboso, erro de configuração ou simplesmente porque o dado fica visível em lugares errados — como mensagens de erro, logs públicos ou respostas HTTP.

Ejemplo

Um endpoint que lista pedidos expõe o CPF de outros clientes na resposta JSON sem validar se aquele usuário tem permissão; ou uma página de erro de servidor exibe o caminho completo dos arquivos e credenciais do banco de dados; ou a API retorna tokens de sessão em histórico de navegação.

Cómo mitigar

Implemente controle de acesso baseado em papéis (RBAC), filtre sempre os dados retornados por contexto do usuário autenticado, nunca exponha informação sensível em logs ou mensagens de erro, e revise regularmente o que a API devolve em cada resposta — especialmente campos como senhas, chaves, CPFs e tokens.

CVE-2021-25519MEDIUMAn improper access control vulnerability in CPLC prior to SMR Dec-2021 Release 1 allows local attackers to access CPLC information without pEPSS 0.1%CVE-2025-68966MEDIUMPermission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiaEPSS 0.1%CVE-2022-30753LOWImproper use of a unique device ID in unprotected SecSoterService prior to SMR Jul-2022 Release 1 allows local attackers to get the device IEPSS 0.1%CVE-2025-58277MEDIUMPermission verification bypass vulnerability in the Camera app. Successful exploitation of this vulnerability may affect service confidentiaEPSS 0.1%CVE-2026-76735MEDIUMAuthenticated Local Sensitive Information Disclosure in HPE Networking Instant OnEPSS 0.1%CVE-2025-66330MEDIUMApp lock verification bypass vulnerability in the file management app. Impact: Successful exploitation of this vulnerability may affect servEPSS 0.1%CVE-2022-33728MEDIUMExposure of sensitive information in Bluetooth prior to SMR Aug-2022 Release 1 allows local attackers to access connected BT macAddress via EPSS 0.1%CVE-2023-23588MEDIUMA vulnerability has been identified in SIMATIC IPC1047 (All versions), SIMATIC IPC1047E (All versions with maxView Storage Manager < 4.09.00EPSS 0.1%CVE-2025-68965MEDIUMPermission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiaEPSS 0.1%CVE-2025-26453MEDIUMIn isContentUriForOtherUser of BluetoothOppSendFileInfo.java, there is a possible cross user data leak due to a logic error in the code. ThiEPSS 0.1%CVE-2022-38686MEDIUMIn wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2022-47367MEDIUMIn bluetooth driver, there is a missing permission check. This could lead to local information disclosure with no additional execution priviEPSS 0.1%CVE-2025-63729CRITICALAn issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA CertifEPSS 0.1%CVE-2025-64311MEDIUMPermission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiaEPSS 0.1%CVE-2022-47324MEDIUMIn wlan driver, there is a possible missing permission check. This could lead to local information disclosure.EPSS 0.1%CVE-2022-47325MEDIUMIn wlan driver, there is a possible missing permission check. This could lead to local information disclosure.EPSS 0.1%CVE-2022-47329MEDIUMIn wlan driver, there is a possible missing permission check. This could lead to local information disclosure.EPSS 0.1%CVE-2022-47328MEDIUMIn wlan driver, there is a possible missing permission check. This could lead to local information disclosure.EPSS 0.1%CVE-2022-47326MEDIUMIn wlan driver, there is a possible missing permission check. This could lead to local information disclosure.EPSS 0.1%CVE-2026-41520HIGHCillium exposes sensitive information included in the cilium-bugtool debug archiveEPSS 0.1%