Falhas do tipo CWE-200

4.993 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2022-38688MEDIUMIn telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privEPSS 0.2%CVE-2026-83279MEDIUMVulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that isEPSS 0.2%CVE-2026-86878MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27. An app may be able to access seEPSS 0.2%CVE-2026-83274MEDIUMVulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that isEPSS 0.2%CVE-2026-63278MEDIUMPackage URLs can be used to exfiltrate arbitrary INI file values and environment variablesEPSS 0.1%CVE-2026-42283HIGHDevSpace UI Server WebSocket CheckOrigin does not validate sourceEPSS 0.1%CVE-2026-90811MEDIUMcosmicstack-labs mercury-agent Shell Permission Manifest permissions.ts PermissionManager.checkShellCommand information disclosureEPSS 0.1%CVE-2026-16398HIGHSite isolation issue in the Graphics componentEPSS 0.1%CVE-2026-90895HIGHMISP Interactive CLI Shell: Authorization Bypass, Credential Exposure, and Terminal InjectionEPSS 0.1%CVE-2026-84530LOWAn information disclosure issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iEPSS 0.1%CVE-2024-39600MEDIUM[CVE-2024-39600] Information Disclosure vulnerability in SAP GUI for WindowsEPSS 0.1%CVE-2025-20611MEDIUMExposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow aEPSS 0.1%CVE-2025-8887MEDIUMIDOR in Usta Information Systems' Aybs InteraktifEPSS 0.1%CVE-2026-79780MEDIUMrclone before v1.75.0 Credential Exposure via S3 RedirectEPSS 0.1%CVE-2026-60886HIGHVulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that arEPSS 0.1%CVE-2022-39904LOWExposure of Sensitive Information vulnerability in Samsung Settings prior to SMR Dec-2022 Release 1 allows local attackers to access the NetEPSS 0.1%CVE-2026-82810MEDIUMextension.vn 2FA Authenticator Extension Background Service Worker chrome.runtime.onMessageExternal.addListener information disclosureEPSS 0.1%CVE-2026-47165MEDIUMImageMagick: Information Disclosure in distributed pixel cache server because it is not using a challenge–response authentication modelEPSS 0.1%CVE-2019-1589MEDIUMCisco Nexus 9000 Series Fabric Switches Application Centric Infrastructure Mode Unmeasured Boot VulnerabilityEPSS 0.1%CVE-2026-41960MEDIUMPermission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%