Fallos del tipo CWE-359

213 resultados

Violação de Privacidade

Ocorre quando a aplicação expõe dados pessoais ou sensíveis sem consentimento do usuário, ou com controle de acesso inadequado. O risco é que informações privadas (credenciais, dados financeiros, localização, etc.) fiquem acessíveis a quem não deveria ter acesso.

Ejemplo

Uma API retorna token de sessão, ID de usuário ou dados de perfil em URLs, logs públicos, ou respostas de erro visíveis; ou um endpoint de listar usuários não valida permissões, permitindo qualquer cliente enumerar dados sensíveis de terceiros.

Cómo mitigar

Implemente controle de acesso granular em cada endpoint sensível; nunca exponha dados pessoais em URLs, logs ou respostas de erro; criptografe dados em trânsito e em repouso; aplique princípio do menor privilégio e audite acessos regularmente.

CVE-2025-3950LOWExposure of Private Personal Information to an Unauthorized Actor in GitLabEPSS 0.3%CVE-2026-55496MEDIUMCloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search because SearchActive() omits the active-status predicateEPSS 0.3%CVE-2024-44113MEDIUMInformation Disclosure vulnerability in the SAP Business Warehouse (BEx Analyzer)EPSS 0.3%CVE-2024-41729MEDIUMInformation Disclosure vulnerability in the SAP NetWeaver BW (BEx Analyzer)EPSS 0.3%CVE-2025-15623CRITICALSparx Pro Cloud Server reveals sensitive information to an unauthenticated userEPSS 0.3%CVE-2026-74966HIGHInformation disclosure in the Form Autofill componentEPSS 0.3%CVE-2026-86904HIGHA privacy issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOSEPSS 0.3%CVE-2024-49386MEDIUMSensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0EPSS 0.2%CVE-2024-37533LOWIBM InfoSphere Information Server information disclosureEPSS 0.2%CVE-2025-20615MEDIUMQardio Heart Health IOS Mobile Application Exposure of Private Personal Information to an Unauthorized ActorEPSS 0.2%CVE-2025-43357MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOEPSS 0.2%CVE-2023-25632—The Android Mobile Whale browser app before 3.0.1.2 allows the attacker to bypass its browser unlock function via 'Open in Whale' feature.EPSS 0.2%CVE-2025-43301LOWA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma EPSS 0.2%CVE-2025-10450HIGHExposure of Private Personal Information to an Unauthorized Actor vulnerability in RTI Connext Professional (Core Libraries) allows Sniffing Network Traffic.EPSS 0.2%CVE-2025-24355HIGHUpdatecli may expose Maven credentials in console outputEPSS 0.2%CVE-2025-13477HIGHOTP Bypass in Digital Operation Services' WifiBuradaEPSS 0.2%CVE-2026-88875MEDIUMAVideo Incomplete API Sanitization Information DisclosureEPSS 0.2%CVE-2026-24321MEDIUMInformation Disclosure vulnerability in SAP Commerce CloudEPSS 0.2%CVE-2025-43452MEDIUMThis issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 26.1 and iPadOS 26.1. Keyboard suggesEPSS 0.2%CVE-2026-6765MEDIUMInformation disclosure in the Form Autofill componentEPSS 0.2%