Fallos del tipo CWE-209

427 resultados

Exposição de Informações Sensíveis em Mensagens de Erro

Quando a aplicação exibe mensagens de erro muito detalhadas ao usuário, revelando informações internas como caminhos de arquivo, versões de software, nomes de banco de dados ou stack traces completos. Um atacante usa essas informações para mapear a infraestrutura e identificar vulnerabilidades conhecidas.

Ejemplo

Um formulário de login retorna 'Erro: usuário admin não encontrado no banco de dados PostgreSQL v13.2' em vez de apenas 'Credenciais inválidas'. Ou uma exceção não tratada mostra o caminho completo /var/www/html/config.php e a linha exata do código que falhou, dando ao atacante um mapa detalhado da aplicação.

Cómo mitigar

Implemente mensagens genéricas para o usuário final ('Dados inválidos') e registre os detalhes técnicos apenas em logs internos que o usuário não acessa. Desative o modo debug em produção e configure tratamento de exceções customizado que nunca exponha stack traces, caminhos ou versões de componentes.

CVE-2022-2508MEDIUMIn affected versions of Octopus Server it is possible to reveal the existence of resources in a space that the user does not have access to EPSS 0.5%CVE-2024-45817HIGHx86: Deadlock in vlapic_error()EPSS 0.5%CVE-2023-33181MEDIUMSensitive Information Disclosure abusing Stack Trace in Xibo CMSEPSS 0.5%CVE-2024-35156MEDIUMIBM MQ information disclosureEPSS 0.5%CVE-2022-43891LOWIBM Security Verify Privilege information disclosureEPSS 0.5%CVE-2022-40292MEDIUMUnauthenticated username enumeration in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC.EPSS 0.5%CVE-2024-13535MEDIUMActionwear products sync <= 2.3.2 - Unauthenticated Full Patch DisclosureEPSS 0.5%CVE-2023-27860MEDIUMIBM Maximo Asset Management information disclosureEPSS 0.5%CVE-2023-6839MEDIUMDue to improper error handling, a REST API resource could expose a server side error containing an internal WSO2 specific package name in thEPSS 0.5%CVE-2023-37489MEDIUMInformation Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Version Management System)EPSS 0.5%CVE-2024-31844MEDIUMAn issue was discovered in Italtel Embrace 1.6.4. The server does not properly handle application errors. In some cases, this leads to a disEPSS 0.5%CVE-2025-20150MEDIUMCisco Nexus Dashboard Username Enumeration VulnerabilityEPSS 0.5%CVE-2026-53906MEDIUMPath Disclosure and Path Traversal in MCOEPSS 0.5%CVE-2025-24552MEDIUMWordPress Paytium plugin <= 4.4.11 - Full Path Disclosure (FPD) vulnerabilityEPSS 0.5%CVE-2022-32756LOWIBM Security Verify Directory information disclosureEPSS 0.5%CVE-2025-32238MEDIUMWordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.5.5 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2026-40245HIGHFree5GC: UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authenticationEPSS 0.5%CVE-2024-28285CRITICALA Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reEPSS 0.5%CVE-2024-35232LOWgithub.com/huandu/facebook may expose access_token in error messageEPSS 0.5%CVE-2026-66306MEDIUMSkype for Business Information Disclosure VulnerabilityEPSS 0.5%