CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,137 vulnerabilities with CWE-532
CVE-2021-32570 MEDIUM
Ericsson Network Manager < 21.2 - Information Disclosure via Log File Access
CVSS 4.9
CVE-2021-43271 MEDIUM
Riverbed AppResponse <11.12 - Info Disclosure
CVSS 6.8
CVE-2021-38939 MEDIUM
IBM QRadar SIEM <7.5 - Info Disclosure
CVSS 5.3
CVE-2021-45103 HIGH
HTCondor 8.9.4-9.0.9 and 9.1.0-9.5.0 - Unauthorized S3 File Access via Log File Information Disclosure
CVSS 8.1
CVE-2021-39739 LOW
Android 12L - Local Information Disclosure via ArrayMap Log Leak
CVSS 3.3
CVE-2021-39715 MEDIUM
Android - Kernel Memory Address Disclosure in __show_regs
CVSS 4.4
CVE-2021-20180 MEDIUM
Ansible < 2.9.18 and 2.8.0a1-2.8.19 - Credential Exposure in Console Log via bitbucket_pipeline_variable Module
CVSS 5.5
CVE-2021-41543 MEDIUM
Climatix POL909 Firmware < 11.36 (AWM) and < 11.44 (AWB) - Authenticated Information Disclosure via Log File Handling
CVSS 6.5
CVE-2021-25009 MEDIUM
CorreosExpress <2.6.0 - Info Disclosure
CVSS 5.3
CVE-2021-36289 HIGH
Dell VNX2 OE for File <8.1.21.266 - Info Disclosure
CVSS 7.8
CVE-2021-41808 LOW
M-Files Server < 21.11.10775.0 - Sensitive Information Disclosure in Federated Authentication Logs
CVSS 2.0
CVE-2021-44234 MEDIUM
SAP Business One 10.0 - Sensitive Information Exposure in Extended Log
CVSS 5.5
CVE-2021-39032 MEDIUM
IBM Sterling Gentran:Server for Microsoft Windows 5.3 - Sensitive Information Exposure in Log Files
CVSS 5.5
CVE-2021-45449 MEDIUM
Docker Desktop 4.3.0 and 4.3.1 - Sensitive Information Exposure in Log Files
CVSS 5.5
CVE-2021-45034 HIGH
Siemens CP-8000 and CP-8021/8022 Master Modules < V16.20 - Unauthenticated Sensitive Data Exposure via Web Server
CVSS 7.5
CVE-2021-34797 HIGH
Apache Geode < 1.12.4 and 1.13.4 - Sensitive Information Exposure in Log Files
CVSS 7.5
CVE-2021-36318 MEDIUM
Dell EMC Avamar <19.5 - Info Disclosure
CVSS 6.7
CVE-2021-0997 MEDIUM
Android 12 - Local Information Disclosure via GnssNetworkConnectivityHandler Log
CVSS 5.5
CVE-2021-0991 LOW
Android 12 - Bluetooth MAC Address Disclosure via AdvancedBluetoothDetailsHeaderController Log
CVSS 2.4
CVE-2021-37861 MEDIUM
Mattermost < 6.0.2 - Password Exposure in Audit Logs
CVSS 5.8
CVE-2021-34800 HIGH
Acronis Agent < c21.06 - Sensitive Information Disclosure via Log File
CVSS 7.5
CVE-2021-21561 HIGH
Dell PowerScale OneFS 8.1.2 - Sensitive Information Exposure in Log Files
CVSS 7.8
CVE-2021-37036 MEDIUM
FusionCompute 6.5.1 and eCNS280_TD V100R005C00/C10 - Information Disclosure via Log File
CVSS 5.5
CVE-2021-36340 HIGH
Dell EMC SCG <5.00.00.10 - Info Disclosure
CVSS 7.8
CVE-2021-22030 MEDIUM
Greenplum < 5.28.14 - Sensitive Information Exposure in Log Files
CVSS 6.5
Details
Vulnerabilities 1,137
Exploit Likelihood Medium