CWE-536: Servlet Runtime Error Message Containing Sensitive Information

Variant Incomplete Simple

CWE版本: 4.18

更新日期: 2025-09-09

弱点描述

A servlet error message indicates that there exists an unhandled exception in your web application code and may provide useful information to an attacker.

常见后果

影响范围: Confidentiality

技术影响: Read Application Data

说明: The error message may contain the location of the file in which the offending function is located. This may disclose the web root's absolute path as well as give the attacker the location of application files or configuration information. It may even disclose the portion of code that failed. In many cases, an attacker can use the data to launch further attacks against the system.

引入模式

阶段 说明
Implementation -
关键信息

CWE ID: CWE-536

抽象级别: Variant

结构: Simple

状态: Incomplete

相关弱点