CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,137 vulnerabilities with CWE-532
CVE-2020-5225 MEDIUM
SimpleSAMLphp < 1.18.4 - Log Injection via Error Report ID Parameter
CVSS 4.4
CVE-2020-7215 MEDIUM
Gallagher Command Centre <7.90.991, 8.00<8.00.1161, 8.10<8.10.1134 - Sensitive Info Disclosure
CVSS 5.5
CVE-2019-25683 MEDIUM
FileZilla 3.40.0 Denial of Service via Local Search
CVSS 6.2
CVE-2019-4706 LOW
IBM Security Identity Manager Virtual Appliance <7.0.2 - Info Discl...
CVSS 2.7
CVE-2019-20852 HIGH
Mattermost Mobile < 1.26.0 - Sensitive Information Exposure in Local Logs
CVSS 7.5
CVE-2019-4286 MEDIUM
IBM Maximo Anywhere <7.6.3.1 - Info Disclosure
CVSS 4.3
CVE-2019-20625 LOW
Samsung Android N(7.1) and O(8.x) - Information Disclosure via ion debugfs Driver
CVSS 3.3
CVE-2019-16528 HIGH
MediaWiki AbuseFilter - Sensitive Information Exposure in AbuseLog Revision Data
CVSS 7.5
CVE-2019-18576 MEDIUM
Dell EMC XtremIO XMS <6.3.0 - Info Disclosure
CVSS 6.7
CVE-2019-19756 HIGH
Lenovo XClarity Administrator 2.6.0 - Sensitive Information Disclosure in Log Files
CVSS 7.9
CVE-2019-16157 MEDIUM
Fortinet FortiWeb <6.2.0 - Info Disclosure
CVSS 6.5
CVE-2019-16204 HIGH
Brocade Fabric OS <v7.4.2f,v8.2.2a,v8.1.2j,v8.2.1d - Info Disclosure
CVSS 7.5
CVE-2019-16203 HIGH
Brocade Fabric OS <8.2.2a, 8.2.1d - Info Disclosure
CVSS 7.5
CVE-2019-18193 HIGH
Unisys Stealth 3.4.108.0, 3.4.209.x, 4.0.027.x, 4.0.114 - Sensitive Information Disclosure in Log Files
CVSS 7.5
CVE-2019-14885 MEDIUM
JBoss Enterprise Application Platform < 7.2.6 - Sensitive Information Disclosure in Log Files via CLI Reload Command
CVSS 4.3
CVE-2019-18244 MEDIUM
OSIsoft PI Vision - Sensitive Information Exposure in Log Files
CVSS 4.7
CVE-2019-11292 MEDIUM
Pivotal Ops Manager Sensitive Information Disclosure in Tomcat Access Log
CVSS 6.5
CVE-2019-14854 MEDIUM
OpenShift Container Platform 4 - Sensitive Information Exposure in Static Pod Logs
CVSS 6.5
CVE-2019-14864 MEDIUM
Ansible 2.7.0-2.7.14, 2.8.0-2.8.6, 2.9.0 - Sensitive Information Disclosure via Log File
CVSS 6.5
CVE-2019-3429 MEDIUM
ZTE ZXCLOUD GoldenData VAP <= V4.01.01.02 - Unauthenticated Sensitive Information Disclosure via Log File
CVSS 5.3
CVE-2019-19150 MEDIUM
BIG-IP APM <15.0.1.1 - Info Disclosure
CVSS 4.9
CVE-2019-15235 MEDIUM
Control WebPanel 0.9.8.856-0.9.8.864 - Sensitive Information Disclosure via Session and Log Files
CVSS 6.5
CVE-2019-14782 MEDIUM
Webpanel < 0.9.8.864 - Log Information Exposure
CVSS 6.5
CVE-2019-10695 MEDIUM
Puppet Continuous Delivery < 1.2.1 - Sensitive Information Exposure in Log File
CVSS 6.5
CVE-2019-11293 MEDIUM
Cloudfoundry Cf-deployment < 12.12.0 - Log Information Exposure
CVSS 6.5
Details
Vulnerabilities 1,137
Exploit Likelihood Medium