Falhas do tipo CWE-209

427 resultados

Exposição de Informações Sensíveis em Mensagens de Erro

A aplicação expõe detalhes técnicos internos (caminhos de arquivos, versões de banco de dados, stack traces, credenciais) em mensagens de erro exibidas ao usuário. Um atacante usa essas informações para mapear a infraestrutura, identificar versões vulneráveis e planejar ataques mais precisos.

Exemplo

Um aplicativo PHP exibe erro de conexão com banco: 'Fatal error: Cannot connect to MySQL at /var/www/html/db.php line 42, user: root@192.168.1.5'. O atacante descobre o caminho do servidor, versão do MySQL, IP interno e usuário administrativo — tudo que precisa para explorar o sistema.

Como mitigar

Exiba mensagens genéricas ao usuário ('Erro ao processar requisição') e registre os detalhes reais em logs do servidor que só administradores acessam. Configure o ambiente de produção para desabilitar stack traces visíveis (debug=false em frameworks).

CVE-2025-52023MEDIUMA vulnerability in the PHP backend of gemscms.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to trigger detailed erroEPSS 0.5%CVE-2025-52022MEDIUMA vulnerability in the PHP backend of gemsloyalty.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to trigger detailed EPSS 0.5%CVE-2022-4870MEDIUMIn affected versions of Octopus Deploy it is possible to discover network details via error messageEPSS 0.4%CVE-2024-35119MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.4%CVE-2024-8571MEDIUMerjemin roll_cms views.py information exposureEPSS 0.4%CVE-2023-42475MEDIUMInformation Disclosure Vulnerability in Statutory ReportingEPSS 0.4%CVE-2024-39458LOWWhen Jenkins Structs Plugin 337.v1b_04ea_4df7c8 and earlier fails to configure a build step, it logs a warning message containing diagnosticEPSS 0.4%CVE-2023-0833MEDIUMRed hat a-mq streams: component version with information disclosure flawEPSS 0.4%CVE-2022-4770MEDIUMHitachi Vantara Pentaho Business Analytics Server - Generation of Error Message Containing Sensitive Information EPSS 0.4%CVE-2022-4769MEDIUMHitachi Vantara Pentaho Business Analytics Server - Generation of Error Message Containing Sensitive Information EPSS 0.4%CVE-2025-4166MEDIUMVault May Include Sensitive Data in Error Logs When Using the KV v2 PluginEPSS 0.4%CVE-2024-45658LOWIBM Security Verify Access information disclosureEPSS 0.4%CVE-2023-23474LOWIBM Cognos Controller information disclosureEPSS 0.4%CVE-2022-0563MEDIUMA flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" envirEPSS 0.4%CVE-2024-52043MEDIUMUser enumeration in HubHubEPSS 0.4%CVE-2026-28786MEDIUMOpen WebUI vulnerable to Path Traversal in `POST /api/v1/audio/transcriptions`EPSS 0.4%CVE-2025-68110CRITICALChurchCRM discloses database information on error messageEPSS 0.4%CVE-2024-39751MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.4%CVE-2026-22646MEDIUMCertain error messages returned by the application expose internal system details that should not be visible to end users, providing attackeEPSS 0.4%CVE-2024-13540MEDIUMWooODT Lite – Delivery & pickup date time location for WooCommerce <= 2.5.1 - Unauthenticated Full Path DsiclosureEPSS 0.4%