Falhas do tipo CWE-200

5.020 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2018-9379MEDIUMIn multiple functions of MiniThumbFile.java, there is a possible way to view the thumbnails of deleted photos due to a confused deputy. ThisEPSS 0.1%CVE-2022-33699LOWExposure of Sensitive Information in getDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via lEPSS 0.1%CVE-2022-33687LOWExposure of Sensitive Information in telephony-common.jar prior to SMR Jul-2022 Release 1 allows local attackers to access IMSI via log.EPSS 0.1%CVE-2022-33698LOWExposure of Sensitive Information in Telecom application prior to SMR Jul-2022 Release 1 allows local attackers to access ICCID via log.EPSS 0.1%CVE-2022-33700LOWExposure of Sensitive Information in putDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via lEPSS 0.1%CVE-2022-33693LOWExposure of Sensitive Information in CID Manager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.EPSS 0.1%CVE-2025-58305MEDIUMIdentity authentication bypass vulnerability in the Gallery app. Impact: Successful exploitation of this vulnerability may affect service coEPSS 0.1%CVE-2021-25486LOWExposure of information vulnerability in ipcdump prior to SMR Oct-2021 Release 1 allows an attacker detect device information via analyzing EPSS 0.1%CVE-2025-22430MEDIUMIn isInSignificantPlace of multiple files, there is a possible way to access sensitive information due to a missing permission check. This cEPSS 0.1%CVE-2025-48642MEDIUMIn jump_to_payload of payload.rs, there is a possible information disclosure due to a logic error in the code. This could lead to local infoEPSS 0.1%CVE-2022-24001LOWInformation disclosure vulnerability in Edge Panel prior to Android S(12) allows physical attackers to access screenshot in clipboard via EdEPSS 0.1%CVE-2024-45447MEDIUMAccess control vulnerability in the camera framework module Impact: Successful exploitation of this vulnerability may affect service confideEPSS 0.1%CVE-2025-68959MEDIUMPermission verification bypass vulnerability in the media library module. Impact: Successful exploitation of this vulnerability may affect sEPSS 0.1%CVE-2021-25519MEDIUMAn improper access control vulnerability in CPLC prior to SMR Dec-2021 Release 1 allows local attackers to access CPLC information without pEPSS 0.1%CVE-2025-68966MEDIUMPermission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiaEPSS 0.1%CVE-2026-76735MEDIUMAuthenticated Local Sensitive Information Disclosure in HPE Networking Instant OnEPSS 0.1%CVE-2022-30753LOWImproper use of a unique device ID in unprotected SecSoterService prior to SMR Jul-2022 Release 1 allows local attackers to get the device IEPSS 0.1%CVE-2025-58277MEDIUMPermission verification bypass vulnerability in the Camera app. Successful exploitation of this vulnerability may affect service confidentiaEPSS 0.1%CVE-2022-33728MEDIUMExposure of sensitive information in Bluetooth prior to SMR Aug-2022 Release 1 allows local attackers to access connected BT macAddress via EPSS 0.1%CVE-2023-23588MEDIUMA vulnerability has been identified in SIMATIC IPC1047 (All versions), SIMATIC IPC1047E (All versions with maxView Storage Manager < 4.09.00EPSS 0.1%