CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,138 vulnerabilities with CWE-532
CVE-2018-10855 MEDIUM
Ansible 2.4-2.4.4 and 2.5.0a1-2.5.4 - Sensitive Information Disclosure in Log Files
CVSS 5.9
CVE-2018-1072 MEDIUM
ovirt < 4.2.2 - Sensitive Information Exposure in Log Files via engine-backup
CVSS 5.0
CVE-2018-7682 MEDIUM
Micro Focus Solutions Business Manager < 11.4 - Insertion of Sensitive Information into Log File
CVSS 6.5
CVE-2018-7683 HIGH
Micro Focus Solutions Business Manager < 11.4 - Sensitive Information Exposure in Server Log Files
CVSS 7.5
CVE-2018-12604 HIGH
GreenCMS 2.3.0603 - Info Disclosure
CVSS 7.5
CVE-2018-1117 MEDIUM
ovirt-ansible-roles <1.0.6 - Info Disclosure
CVSS 5.0
CVE-2018-1075 MEDIUM
ovirt-engine < 4.2.3 - Unfiltered Password Exposure in Manual Database Provisioning
CVSS 5.0
CVE-2018-0335 HIGH
Cisco Prime Collaboration Provisioning - Unauthenticated Sensitive Data Exposure via World-Readable Log File
CVSS 7.8
CVE-2018-1241 HIGH
Dell EMC RecoverPoint < 5.1.2 and RecoverPoint for VMs < 5.1.1.3 - Authenticated LDAP Password Exposure in Log Files
CVSS 8.8
CVE-2018-11320 CRITICAL
Octopus Server 2018.4.4-2018.5.1 - Sensitive Information Exposure in Deployment Logs
CVSS 9.8
CVE-2018-8719 MEDIUM
WP Security Audit Log <3.1.1 - Info Disclosure
CVSS 5.3
CVE-2018-3817 MEDIUM
Logstash < 5.6.6 and 6.x < 6.1.2 - Sensitive Information Disclosure in Deprecated Settings Log
CVSS 6.5
CVE-2018-1350 LOW
NetIQ Identity Manager < 4.6 - Sensitive Information Exposure in Driver Log File
CVSS 2.3
CVE-2018-1349 LOW
NetIQ Identity Manager < 4.6 - Sensitive Information Exposure in Driver Log File
CVSS 2.3
CVE-2018-1000123 CRITICAL
Ionic Team Cordova plugin iOS Keychain < 2.0.0 - Sensitive Information Exposure in Log Files
CVSS 9.8
CVE-2018-1000089 HIGH
Anymail django-anymail <1.3 - Info Disclosure
CVSS 7.4
CVE-2018-7204 HIGH
Giribaz File Manager < 5.0.0 - Sensitive Information Disclosure via Log File
CVSS 7.5
CVE-2018-7433 HIGH
iThemes Security < 6.9.0 - Sensitive Information Disclosure in Logs Page
CVSS 7.5
CVE-2018-3609 HIGH
Trend Micro InterScan Messaging Security Virtual Appliance 9.0-9.1 - Sensitive Information Exposure via Log File
CVSS 8.1
CVE-2018-2372 MEDIUM
SAP HANA Extended Application Services 1.0 - Sensitive Information Disclosure in Log File
CVSS 6.5
CVE-2018-1000060 CRITICAL
Sensu Core <1.2.0 - Info Disclosure
CVSS 9.8
CVE-2018-1000018 HIGH
ovirt-hosted-engine-setup <2.2.7 - Info Disclosure
CVSS 7.8
CVE-2018-5693 LOW
LinuxMagic MagicSpam <2.0.14-1 - Info Disclosure
CVSS 3.3
CVE-2017-17675 MEDIUM
BMC Remedy Mid Tier 9.1SP3 - Unauthenticated Log Hijacking via Remote Logging
CVSS 5.3
CVE-2017-18426 LOW
cPanel < 66.0.2 - Unauthorized Domain Log File Access
CVSS 2.7
Details
Vulnerabilities 1,138
Exploit Likelihood Medium