Fallos del tipo CWE-209

432 resultados

Exposição de Informações Sensíveis em Mensagens de Erro

Quando a aplicação exibe mensagens de erro muito detalhadas ao usuário, revelando informações internas como caminhos de arquivo, versões de software, nomes de banco de dados ou stack traces completos. Um atacante usa essas informações para mapear a infraestrutura e identificar vulnerabilidades conhecidas.

Ejemplo

Um formulário de login retorna 'Erro: usuário admin não encontrado no banco de dados PostgreSQL v13.2' em vez de apenas 'Credenciais inválidas'. Ou uma exceção não tratada mostra o caminho completo /var/www/html/config.php e a linha exata do código que falhou, dando ao atacante um mapa detalhado da aplicação.

Cómo mitigar

Implemente mensagens genéricas para o usuário final ('Dados inválidos') e registre os detalhes técnicos apenas em logs internos que o usuário não acessa. Desative o modo debug em produção e configure tratamento de exceções customizado que nunca exponha stack traces, caminhos ou versões de componentes.

CVE-2026-8173MEDIUMInformation Disclosure via 'Copy learned MAC Addresses' FunctionEPSS 0.2%CVE-2026-40969LOWSpring gRPC AuthenticationException message reflected to remote clientEPSS 0.2%CVE-2026-4994MEDIUMwandb OpenUI APIStatusError server.py generic_exception_handler information exposureEPSS 0.2%CVE-2026-33333LOWCombodo iTop: Information disclosure in ajax.render.phpEPSS 0.2%CVE-2026-41730MEDIUMSpring Data REST exposes persistence-layer internals in error responsesEPSS 0.2%CVE-2026-56568LOWHCL iControl is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2024-41983MEDIUMA vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >=EPSS 0.2%CVE-2026-22052MEDIUMONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could alEPSS 0.2%CVE-2025-0941MEDIUMMET ONE 3400+ Potential Credential ExposureEPSS 0.2%CVE-2023-40725MEDIUMA vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application returns inconsistent error messages EPSS 0.2%CVE-2024-6613MEDIUMIncorrect listing of stack framesEPSS 0.2%CVE-2023-28514MEDIUMIBM MQ information disclosureEPSS 0.2%CVE-2022-35640MEDIUMIBM Sterling Partner Engagement Manager information disclosureEPSS 0.2%CVE-2024-52898MEDIUMIBM MQ information disclosureEPSS 0.2%CVE-2026-69247HIGHcryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timingEPSS 0.2%CVE-2026-56571LOWHCL iControl is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2022-34881LOWInformation Exposure Vulnerability in JP1/Automatic OperationEPSS 0.2%CVE-2025-52606MEDIUMHCL iControl was affected by Weak Input Validation vulnerability. .EPSS 0.2%CVE-2025-59853LOWHCL DFXAnalytics is affected by an Improper Error Handling vulnerabilityEPSS 0.2%CVE-2024-41984LOWA vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >=EPSS 0.2%