Falhas do tipo CWE-209

432 resultados

Exposição de Informações Sensíveis em Mensagens de Erro

A aplicação expõe detalhes técnicos internos (caminhos de arquivos, versões de banco de dados, stack traces, credenciais) em mensagens de erro exibidas ao usuário. Um atacante usa essas informações para mapear a infraestrutura, identificar versões vulneráveis e planejar ataques mais precisos.

Exemplo

Um aplicativo PHP exibe erro de conexão com banco: 'Fatal error: Cannot connect to MySQL at /var/www/html/db.php line 42, user: root@192.168.1.5'. O atacante descobre o caminho do servidor, versão do MySQL, IP interno e usuário administrativo — tudo que precisa para explorar o sistema.

Como mitigar

Exiba mensagens genéricas ao usuário ('Erro ao processar requisição') e registre os detalhes reais em logs do servidor que só administradores acessam. Configure o ambiente de produção para desabilitar stack traces visíveis (debug=false em frameworks).

CVE-2025-12365MEDIUMError Messages Wrapped In HTTP HeaderEPSS 0.2%CVE-2025-43777MEDIUMLiferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.QEPSS 0.2%CVE-2023-50355LOWHCL Sametime is impacted by generation of error messages containing sensitive informationEPSS 0.2%CVE-2021-1546MEDIUMCisco SD-WAN Software Information Disclosure VulnerabilityEPSS 0.2%CVE-2025-59016MEDIUMInformation Disclosure via File Abstraction LayerEPSS 0.2%CVE-2021-47161MEDIUMspi: spi-fsl-dspi: Fix a resource leak in an error handling pathEPSS 0.2%CVE-2026-3259HIGHSensitive Data Disclosure in BigQuery via Materialized View Error MessagesEPSS 0.2%CVE-2026-73844LOWCKAN MCP Server: Information disclosure via verbose error reflectionEPSS 0.2%CVE-2025-54562MEDIUMA vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Technical InformatioEPSS 0.2%CVE-2026-1248MEDIUMIBM Business Automation Workflow information leakEPSS 0.2%CVE-2026-47775MEDIUMEnvoy OAuth2 Filter: Padding Oracle via AES-256-CBC Cookie DecryptionEPSS 0.2%CVE-2023-31429MEDIUMMultiple commands print sensitive information in the terminalEPSS 0.2%CVE-2026-5511MEDIUMInformation Disclosure via Diagnostic Interface Due to Improper Input Validation on TP-Link's Archer AX72EPSS 0.2%CVE-2025-43776MEDIUMA Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 202EPSS 0.2%CVE-2026-56620MEDIUMHCL BigFix Mobile is vulnerable to information disclosureEPSS 0.2%CVE-2025-36437MEDIUMIBM Planning Analytics Local is vulnerable to disclosing sensitive informationEPSS 0.2%CVE-2025-66594MEDIUMA vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Detailed messages are displayed on the error page. EPSS 0.2%CVE-2023-34339LOWIn JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's messageEPSS 0.2%CVE-2024-52897MEDIUMIBM MQ information disclosureEPSS 0.2%CVE-2024-3454LOWIn-Fabric Matter Cluster Attribute DisclosureEPSS 0.2%