CWE-117

Medium likelihood

Improper Output Neutralization for Logs

Parent: CWE-116 - Improper Encoding or Escaping of Output

The product constructs a log message from external input, but it does not neutralize or incorrectly neutralizes special elements when the message is written to a log file.

93 vulnerabilities with CWE-117
CVE-2024-32474 HIGH
Sentry <24.4.1 - Info Disclosure
CVSS 7.3
CVE-2024-29022 HIGH
Xibo - XSS
CVSS 8.8
CVE-2024-22356 MEDIUM
IBM App Connect Enterprise <12.0.9.0 - Info Disclosure
CVSS 4.9
CVE-2024-0690 MEDIUM
Ansible-core - Info Disclosure
CVSS 5.0
CVE-2024-0987 MEDIUM
Sichuan Yougou Technology KuERP <1.0.4 - Info Disclosure
CVSS 6.3
CVE-2024-22229 LOW
Dell Unity <5.4 - Info Disclosure
CVSS 3.1
CVE-2023-28952 MEDIUM
IBM Cognos Controller <11.0.0 - Command Injection
CVSS 5.3
CVE-2023-39461 MEDIUM
Triangle MicroWorks SCADA Data Gateway - Code Injection
CVSS 4.4
CVE-2023-6484 MEDIUM
Keycloak - Log Injection
CVSS 5.3
CVE-2023-38020 MEDIUM
IBM SOAR QRadar Plugin App <5.0.3 - Info Disclosure
CVSS 4.3
CVE-2023-7234 MEDIUM
OPCUAServerToolkit - Info Disclosure
CVSS 5.3
CVE-2023-46713 MEDIUM
Fortinet FortiWeb <7.4.0 - Info Disclosure
CVSS 5.3
CVE-2023-6002 MEDIUM
Yugabytedb < 2.14.14.0 - XSS
CVSS 6.5
CVE-2023-46322 CRITICAL
iTerm2 <3.5.0beta12 - SSRF
CVSS 9.8
CVE-2023-46321 CRITICAL
iTerm2 <3.5.0beta12 - Path Traversal
CVSS 9.8
CVE-2023-4065 MEDIUM
Red Hat AMQ Broker Operator - Info Disclosure
CVSS 5.5
CVE-2023-4571 HIGH
Splunk IT Service Intelligence <4.13.3, 4.15.3, 4.17.1 - Code Injec...
CVSS 8.6
CVE-2023-3997 HIGH
Splunk SOAR <6.1.0 - Code Injection
CVSS 8.6
CVE-2023-37275 LOW
Auto-GPT <0.4.3 - Info Disclosure
CVSS 3.1
CVE-2023-36924 MEDIUM
SAP ERP Defense Forces and Public Security - Authenticated Privileg...
CVSS 4.9
CVE-2023-31405 MEDIUM
SAP NetWeaver AS for Java - Info Disclosure
CVSS 5.3
CVE-2023-32712 HIGH
Splunk Enterprise <9.1.0.2, <9.0.5.1, <8.2.11.2 - Code Injection
CVSS 8.6
CVE-2023-1711 MEDIUM
FOXMAN-UN - Info Disclosure
CVSS 4.0
CVE-2023-0595 MEDIUM
EcoStruxure Geo SCADA Expert <October 2022 - Info Disclosure
CVSS 5.3
CVE-2022-1522 MEDIUM
Cognex 3D-A1000 Dimensioning System <1.0.3 (3354) - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 93
Exploit Likelihood Medium