CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,099 vulnerabilities with CWE-532
CVE-2017-1727 MEDIUM
IBM Security Key Lifecycle Manager - Log Information Exposure
CVSS 4.3
CVE-2017-6139 MEDIUM
F5 Big-ip Access Policy Manager - Log Information Exposure
CVSS 5.9
CVE-2017-8001 HIGH
Dell Emc Scaleio - Log Information Exposure
CVSS 8.4
CVE-2017-16946 MEDIUM
MISP <2.4.82 - Info Disclosure
CVSS 4.9
CVE-2017-7550 CRITICAL
Ansible <2.3.3, <2.4.1 - Info Disclosure
CVSS 9.8
CVE-2017-1000171 CRITICAL
Mahara Mobile <1.2.1 - Info Disclosure
CVSS 9.8
CVE-2017-15366 CRITICAL
Ndoc < 7.4 - Log Information Exposure
CVSS 9.8
CVE-2017-6165 CRITICAL
F5 Big-ip Access Policy Manager - Log Information Exposure
CVSS 9.8
CVE-2017-15572 HIGH
Redmine < 3.2.5 - Log Information Exposure
CVSS 7.5
CVE-2017-0380 MEDIUM
Tor < 0.2.8.14 - Log Information Exposure
CVSS 5.9
CVE-2017-11134 MEDIUM
Stashcat Heinekingmedia < 1.7.5 - Log Information Exposure
CVSS 6.5
CVE-2017-6709 CRITICAL
Cisco Ultra Services Framework < 5.0.2 - Information Disclosure
CVSS 9.8
CVE-2017-9615 CRITICAL
Cognito Software Moneyworks <8.0.3 - Info Disclosure
CVSS 9.8
CVE-2017-3744 MEDIUM
Lenovo System x - Info Disclosure
CVSS 6.5
CVE-2017-4955 CRITICAL
Pivotal PCF Elastic Runtime <1.6.65-<1.9.5 - Info Disclosure
CVSS 9.8
CVE-2017-8075 CRITICAL
Tp-link Tl-sg108e Firmware - Log Information Exposure
CVSS 9.8
CVE-2017-8074 CRITICAL
Tp-link Tl-sg108e Firmware - Log Information Exposure
CVSS 9.8
CVE-2017-7214 CRITICAL
OpenStack Nova <15.0.1 - Info Disclosure
CVSS 9.8
CVE-2017-5153 HIGH
OSIsoft PI Coresight <2016 R2 - Info Disclosure
CVSS 7.8
CVE-2017-5549 MEDIUM
Linux Kernel < 4.9.4 - Log Information Exposure
CVSS 5.5
CVE-2017-5137 MEDIUM
SendQuick Entera/Avera <2HF16 - Info Disclosure
CVSS 6.2
CVE-2016-10819 MEDIUM
Cpanel < 11.50.6.2 - Log Information Exposure
CVSS 6.5
CVE-2016-10526 HIGH
Module <0.9.1 - Info Disclosure
CVSS 8.6
CVE-2016-0898 CRITICAL
MySQL for PCF tiles <1.7.10 - Info Disclosure
CVSS 10.0
CVE-2016-10362 MEDIUM
Elasticsearch Output Plugin < 5.0.0 - Information Disclosure
CVSS 6.5
Details
Vulnerabilities 1,099
Exploit Likelihood Medium