Falhas do tipo CWE-209

427 resultados

Exposição de Informações Sensíveis em Mensagens de Erro

A aplicação expõe detalhes técnicos internos (caminhos de arquivos, versões de banco de dados, stack traces, credenciais) em mensagens de erro exibidas ao usuário. Um atacante usa essas informações para mapear a infraestrutura, identificar versões vulneráveis e planejar ataques mais precisos.

Exemplo

Um aplicativo PHP exibe erro de conexão com banco: 'Fatal error: Cannot connect to MySQL at /var/www/html/db.php line 42, user: root@192.168.1.5'. O atacante descobre o caminho do servidor, versão do MySQL, IP interno e usuário administrativo — tudo que precisa para explorar o sistema.

Como mitigar

Exiba mensagens genéricas ao usuário ('Erro ao processar requisição') e registre os detalhes reais em logs do servidor que só administradores acessam. Configure o ambiente de produção para desabilitar stack traces visíveis (debug=false em frameworks).

CVE-2022-2508MEDIUMIn affected versions of Octopus Server it is possible to reveal the existence of resources in a space that the user does not have access to EPSS 0.5%CVE-2024-45817HIGHx86: Deadlock in vlapic_error()EPSS 0.5%CVE-2023-33181MEDIUMSensitive Information Disclosure abusing Stack Trace in Xibo CMSEPSS 0.5%CVE-2024-35156MEDIUMIBM MQ information disclosureEPSS 0.5%CVE-2022-43891LOWIBM Security Verify Privilege information disclosureEPSS 0.5%CVE-2022-40292MEDIUMUnauthenticated username enumeration in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC.EPSS 0.5%CVE-2024-13535MEDIUMActionwear products sync <= 2.3.2 - Unauthenticated Full Patch DisclosureEPSS 0.5%CVE-2023-27860MEDIUMIBM Maximo Asset Management information disclosureEPSS 0.5%CVE-2023-6839MEDIUMDue to improper error handling, a REST API resource could expose a server side error containing an internal WSO2 specific package name in thEPSS 0.5%CVE-2023-37489MEDIUMInformation Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Version Management System)EPSS 0.5%CVE-2024-31844MEDIUMAn issue was discovered in Italtel Embrace 1.6.4. The server does not properly handle application errors. In some cases, this leads to a disEPSS 0.5%CVE-2025-20150MEDIUMCisco Nexus Dashboard Username Enumeration VulnerabilityEPSS 0.5%CVE-2026-53906MEDIUMPath Disclosure and Path Traversal in MCOEPSS 0.5%CVE-2025-24552MEDIUMWordPress Paytium plugin <= 4.4.11 - Full Path Disclosure (FPD) vulnerabilityEPSS 0.5%CVE-2022-32756LOWIBM Security Verify Directory information disclosureEPSS 0.5%CVE-2025-32238MEDIUMWordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.5.5 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2026-40245HIGHFree5GC: UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authenticationEPSS 0.5%CVE-2024-28285CRITICALA Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reEPSS 0.5%CVE-2024-35232LOWgithub.com/huandu/facebook may expose access_token in error messageEPSS 0.5%CVE-2026-66306MEDIUMSkype for Business Information Disclosure VulnerabilityEPSS 0.5%