Falhas do tipo CWE-497

369 resultados

Divulgação de Informações Sensíveis

Ocorre quando a aplicação expõe dados sensíveis (credenciais, tokens, caminhos internos, versões de software) através de mensagens de erro, logs, respostas HTTP, comentários no código ou outros canais acessíveis. O risco é que um atacante coleta essas informações para preparar ataques mais direcionados ou escalar privilégios.

Exemplo

Um erro de banco de dados não tratado exibe a query SQL completa e credenciais do BD ao usuário; ou um arquivo .git exposto no servidor revela histórico de commits com senhas hardcoded; ou stack traces detalhados em respostas de API revelam caminhos internos e bibliotecas desatualizadas.

Como mitigar

Implemente tratamento genérico de erros (nunca expor detalhes técnicos ao usuário final), configure logs seguros sem dados sensíveis, revise comentários e metadados antes de deploy, desabilite debug em produção, e escaneie repositórios antes de publicar (buscar secrets e arquivo .git).

CVE-2025-53364MEDIUMParse Server exposes the data schema via GraphQL APIEPSS 0.8%CVE-2026-41459MEDIUMXerte Online Toolkits Path Disclosure via /setupEPSS 0.8%CVE-2021-1234MEDIUMCisco SD-WAN vManage Information Disclosure VulnerabilitiesEPSS 0.8%CVE-2025-34442MEDIUMAVideo < 20.1 System Path Disclosure via Public APIEPSS 0.8%CVE-2024-25634HIGHIDOR make user can read e-mail log sent by other eventsEPSS 0.7%CVE-2025-59582MEDIUMWordPress Ajax Load More Plugin <= 7.6.0.2 - Sensitive Data Exposure VulnerabilityEPSS 0.7%CVE-2023-2541MEDIUMSensitive information disclosure in KNIME Hub Web ApplicationEPSS 0.6%CVE-2023-41366MEDIUMInformation Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP PlatformEPSS 0.6%CVE-2018-25358HIGHD-Link DIR601 2.02NA Credential Disclosure via my_cgi.cgiEPSS 0.6%CVE-2024-36070HIGHtine before 2023.11.8, when an LDAP backend is used, allows anonymous remote attackers to obtain sensitive authentication information via seEPSS 0.6%CVE-2025-34171MEDIUMCasaOS <= 0.4.15 Unauthenticated File and Debug Data ExposureEPSS 0.6%CVE-2025-30686HIGHVulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: EMC). Supported versions thatEPSS 0.6%CVE-2020-36922MEDIUMSony BRAVIA Digital Signage 1.7.8 Unauthenticated System API Information DisclosureEPSS 0.6%CVE-2025-27934HIGHInformation disclosure of authentication information in the specific service vulnerability exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If EPSS 0.6%CVE-2023-20111MEDIUMA vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker EPSS 0.6%CVE-2025-22222HIGHVMware Aria Operations information disclosure vulnerability (CVE-2025-22222)EPSS 0.5%CVE-2023-50959MEDIUMIBM Cloud Pak for Business Automation information disclosureEPSS 0.5%CVE-2025-46421MEDIUMLibsoup: information disclosure may leads libsoup client sends authorization header to a different host when being redirected by a serverEPSS 0.5%CVE-2024-10240MEDIUMExposure of Sensitive System Information to an Unauthorized Control Sphere in GitLabEPSS 0.5%CVE-2025-32792HIGHses's global contour bindings leak into Compartment lexical scopeEPSS 0.5%