CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,137 vulnerabilities with CWE-532
CVE-2020-2043 LOW
PAN-OS 8.1.0-8.1.15 - Sensitive Information Exposure in Configuration Logs
CVSS 3.3
CVE-2020-24566 HIGH
Octopus Deploy <2020.3.4-2020.4.1 - Info Disclosure
CVSS 7.5
CVE-2020-7322 MEDIUM
McAfee Endpoint Security < 10.7.0 - Sensitive Information Disclosure via Debug Log
CVSS 4.7
CVE-2020-3541 MEDIUM
Cisco Webex Meetings and Teams - Sensitive Information Exposure via Media Engine Log Files
CVSS 4.4
CVE-2020-25046 MEDIUM
Android O(8.x), P(9.0), Q(10.0) - Kernel Address Information Leak via USB Driver Logging
CVSS 5.5
CVE-2020-14518 MEDIUM
Philips DreamMapper < 2.24 - Sensitive Information Disclosure in Log Files
CVSS 5.3
CVE-2020-3447 MEDIUM
Cisco Email Security Appliance <13.5.1 & Content Security Management Appliance <13.6.1-201 Sensitive Info Disclosure
CVSS 5.5
CVE-2020-6653 LOW
Eaton SecureConnect < 1.7.3 - Sensitive Information Exposure via Logcat
CVSS 3.8
CVE-2020-6295 HIGH
SAP Adaptive Server Enterprise 16.0 - Info Disclosure
CVSS 7.8
CVE-2020-15829 MEDIUM
JetBrains TeamCity < 2019.2.3 - Sensitive Information Disclosure in Build Logs
CVSS 5.3
CVE-2020-5414 MEDIUM
VMware Tanzu Application Service - Info Disclosure
CVSS 5.7
CVE-2020-4498 MEDIUM
IBM MQ Appliance 9.1.0.0-9.1.0.5 and 9.1.0.0-9.1.9.9 - Sensitive Information Exposure in Trace Files
CVSS 4.4
CVE-2020-4405 MEDIUM
IBM Verify Gateway 1.0.0-1.0.1 - Authenticated Sensitive Information Disclosure via World-Readable Log Files
CVSS 4.3
CVE-2020-6938 HIGH
Tableau Server 10.5-2020.x - Sensitive Information Disclosure in Log Files
CVSS 7.5
CVE-2020-15095 MEDIUM
npm < 6.14.6 - Information Exposure via Log File
CVSS 4.4
CVE-2020-15581 MEDIUM
Android O(8.x), P(9.0), Q(10.0) - Kernel Virtual Address Exposure via Shared Memory Logging
CVSS 5.3
CVE-2020-5908 MEDIUM
BIG-IP APM <12.1.5, <11.6.5.2 - Info Disclosure
CVSS 5.5
CVE-2020-10750 HIGH
jaegertracing/jaeger <1.18.1 - Info Disclosure
CVSS 7.1
CVE-2020-14470 MEDIUM
Octopus Deploy 2018.8.0-2019.x < 2019.12.2 - Authenticated Sensitive Information Disclosure in Log Files
CVSS 6.5
CVE-2020-4477 MEDIUM
IBM Spectrum Protect Plus 10.1.0-10.1.5 - Sensitive Information Disclosure in Virgo Log File
CVSS 6.5
CVE-2020-10752 HIGH
OpenShift API Server - Info Disclosure
CVSS 7.5
CVE-2020-3930 MEDIUM
GeoVision Door Access Control - Info Disclosure
CVSS 4.0
CVE-2020-12023 LOW
Philips IntelliBridge Enterprise < B.12 - Sensitive Information Exposure in Transaction Logs
CVSS 2.0
CVE-2020-13223 HIGH
HashiCorp Vault <1.3.6, <1.4.2 - Info Disclosure
CVSS 7.5
CVE-2020-13881 HIGH
pam_tacplus 1.3.8-1.5.1 - Sensitive Information Disclosure in Debug Logging
CVSS 7.5
Details
Vulnerabilities 1,137
Exploit Likelihood Medium