Falhas do tipo CWE-209

432 resultados

Exposição de Informações Sensíveis em Mensagens de Erro

A aplicação expõe detalhes técnicos internos (caminhos de arquivos, versões de banco de dados, stack traces, credenciais) em mensagens de erro exibidas ao usuário. Um atacante usa essas informações para mapear a infraestrutura, identificar versões vulneráveis e planejar ataques mais precisos.

Exemplo

Um aplicativo PHP exibe erro de conexão com banco: 'Fatal error: Cannot connect to MySQL at /var/www/html/db.php line 42, user: root@192.168.1.5'. O atacante descobre o caminho do servidor, versão do MySQL, IP interno e usuário administrativo — tudo que precisa para explorar o sistema.

Como mitigar

Exiba mensagens genéricas ao usuário ('Erro ao processar requisição') e registre os detalhes reais em logs do servidor que só administradores acessam. Configure o ambiente de produção para desabilitar stack traces visíveis (debug=false em frameworks).

CVE-2026-8173MEDIUMInformation Disclosure via 'Copy learned MAC Addresses' FunctionEPSS 0.2%CVE-2026-40969LOWSpring gRPC AuthenticationException message reflected to remote clientEPSS 0.2%CVE-2026-4994MEDIUMwandb OpenUI APIStatusError server.py generic_exception_handler information exposureEPSS 0.2%CVE-2026-33333LOWCombodo iTop: Information disclosure in ajax.render.phpEPSS 0.2%CVE-2026-41730MEDIUMSpring Data REST exposes persistence-layer internals in error responsesEPSS 0.2%CVE-2026-56568LOWHCL iControl is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2024-41983MEDIUMA vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >=EPSS 0.2%CVE-2026-22052MEDIUMONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could alEPSS 0.2%CVE-2025-0941MEDIUMMET ONE 3400+ Potential Credential ExposureEPSS 0.2%CVE-2023-40725MEDIUMA vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application returns inconsistent error messages EPSS 0.2%CVE-2024-6613MEDIUMIncorrect listing of stack framesEPSS 0.2%CVE-2023-28514MEDIUMIBM MQ information disclosureEPSS 0.2%CVE-2022-35640MEDIUMIBM Sterling Partner Engagement Manager information disclosureEPSS 0.2%CVE-2024-52898MEDIUMIBM MQ information disclosureEPSS 0.2%CVE-2026-69247HIGHcryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timingEPSS 0.2%CVE-2026-56571LOWHCL iControl is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2022-34881LOWInformation Exposure Vulnerability in JP1/Automatic OperationEPSS 0.2%CVE-2025-52606MEDIUMHCL iControl was affected by Weak Input Validation vulnerability. .EPSS 0.2%CVE-2025-59853LOWHCL DFXAnalytics is affected by an Improper Error Handling vulnerabilityEPSS 0.2%CVE-2024-41984LOWA vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >=EPSS 0.2%