Falhas do tipo CWE-209

427 resultados

Exposição de Informações Sensíveis em Mensagens de Erro

A aplicação expõe detalhes técnicos internos (caminhos de arquivos, versões de banco de dados, stack traces, credenciais) em mensagens de erro exibidas ao usuário. Um atacante usa essas informações para mapear a infraestrutura, identificar versões vulneráveis e planejar ataques mais precisos.

Exemplo

Um aplicativo PHP exibe erro de conexão com banco: 'Fatal error: Cannot connect to MySQL at /var/www/html/db.php line 42, user: root@192.168.1.5'. O atacante descobre o caminho do servidor, versão do MySQL, IP interno e usuário administrativo — tudo que precisa para explorar o sistema.

Como mitigar

Exiba mensagens genéricas ao usuário ('Erro ao processar requisição') e registre os detalhes reais em logs do servidor que só administradores acessam. Configure o ambiente de produção para desabilitar stack traces visíveis (debug=false em frameworks).

CVE-2026-45728HIGHAlgernon: Single-file mode unconditionally enables debug modeEPSS 0.3%CVE-2025-20002MEDIUMGMOD Apollo Generation of Error Message Containing Sensitive InformationEPSS 0.3%CVE-2025-13978MEDIUMGeneration of Error Message Containing Sensitive Information in GitLabEPSS 0.3%CVE-2024-51460MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.3%CVE-2026-78693MEDIUMIncomplete redaction re-attaches the original error path in AshGraphql, leaking internal field namesEPSS 0.3%CVE-2025-25045MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.3%CVE-2026-59943MEDIUMDompdf: Embedded SVG images can leak existence of files and directories within the filesystemEPSS 0.3%CVE-2023-40457The BGP daemon in Extreme Networks ExtremeXOS (aka EXOS) 30.7.1.1 allows an attacker (who is not on a directly connected network) to cause aEPSS 0.3%CVE-2023-38017MEDIUMMultiple Vulnerabilities in IBM Cloud Pak SystemEPSS 0.3%CVE-2020-2505LOWSensitive information via generation of error messages vulnerability in QESEPSS 0.3%CVE-2025-66549LOWNextcloud Desktop discloses information when attempting to lock a file inside a end-to-end encrypted directoryEPSS 0.3%CVE-2026-54561MEDIUMMCP Memory Keeper: Arbitrary local file read in mcp-memory-keeper context_import via unvalidated filePathEPSS 0.3%CVE-2023-38281MEDIUMMultiple Vulnerabilities in IBM Cloud Pak SystemEPSS 0.3%CVE-2024-11625HIGHInformation Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affects Sitefinity: from EPSS 0.3%CVE-2026-1030MEDIUMMultiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration AgentEPSS 0.3%CVE-2025-0279MEDIUMHCL Traveler is affected by generation of error messages containing sensitive informationEPSS 0.3%CVE-2026-11904MEDIUMSecurity vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.3%CVE-2024-37162MEDIUMzsa Generates Error Messages Containing Sensitive InformationEPSS 0.3%CVE-2026-47248MEDIUMParse Server: GraphQL "Did you mean" validation suggestions disclose schema to unauthenticated callersEPSS 0.3%CVE-2024-37524MEDIUMIBM Analytics Content Hub information disclosureEPSS 0.3%