CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,138 vulnerabilities with CWE-532
CVE-2017-18423 LOW
cPanel 56.0.1-56.0.51 - Sensitive Information Exposure via Domain Log File
CVSS 3.3
CVE-2017-18412 LOW
cPanel < 56.0.52 - Sensitive Information Exposure via Apache Log File Permissions
CVSS 2.5
CVE-2017-1198 LOW
IBM BigFix Compliance <1.9.91 - Info Disclosure
CVSS 3.7
CVE-2017-2621 MEDIUM
OpenStack Orchestration <8.0.0, 6.1.0, 7.0.2 - Info Disclosure
CVSS 5.5
CVE-2017-15113 HIGH
ovirt-engine <4.1.7.6 - Info Disclosure
CVSS 7.2
CVE-2017-1795 MEDIUM
IBM WebSphere MQ Managed File Transfer 7.5-9.0.4 - Sensitive Information Exposure via Trace Logs
CVSS 4.4
CVE-2017-1480 MEDIUM
IBM Security Access Manager 8.0.0-8.0.1.6 and 9.0.0-9.0.3.1 - Sensitive Information Disclosure in Log Files
CVSS 4.3
CVE-2017-2592 MEDIUM
oslo.middleware < 3.8.1, 3.19.1, 3.23.1 - Sensitive Information Disclosure in Error Logs
CVSS 5.9
CVE-2017-1733 MEDIUM
IBM QRadar 7.3 - Sensitive Information Exposure in Log Files
CVSS 4.0
CVE-2017-9278 LOW
NetIQ Identity Manager <4.0.2.0 - Info Disclosure
CVSS 3.3
CVE-2017-7434 LOW
NetIQ Identity Manager <4.6 - Info Disclosure
CVSS 3.3
CVE-2017-9271 LOW
zypper - Sensitive Information Exposure via HTTP Proxy Credential Logging
CVSS 3.3
CVE-2017-1727 MEDIUM
IBM Security Key Lifecycle Manager 2.5-2.7 - Sensitive Information Disclosure in Error Messages
CVSS 4.3
CVE-2017-6139 MEDIUM
F5 BIG-IP APM 12.1.2, 13.0.0 - Sensitive Information Disclosure in Log Files
CVSS 5.9
CVE-2017-8001 HIGH
EMC ScaleIO 2.0.1.x - Sensitive Information Disclosure in Log Files
CVSS 8.4
CVE-2017-16946 MEDIUM
MISP 2.4.82 - Sensitive Information Disclosure in Audit Log
CVSS 4.9
CVE-2017-7550 CRITICAL
Ansible <2.3.3, <2.4.1 - Info Disclosure
CVSS 9.8
CVE-2017-1000171 CRITICAL
Mahara Mobile <1.2.1 - Info Disclosure
CVSS 9.8
CVE-2017-15366 CRITICAL
ndoc < 7.4 - Sensitive Information Exposure via Cleartext Password in Log File
CVSS 9.8
CVE-2017-6165 CRITICAL
F5 BIG-IP - Sensitive Information Disclosure in Log File
CVSS 9.8
CVE-2017-15572 HIGH
Redmine < 3.2.6 and 3.3.x < 3.3.3 - Sensitive Information Exposure via Referer Log
CVSS 7.5
CVE-2017-0380 MEDIUM
Tor < 0.2.8.14 - Log Information Exposure
CVSS 5.9
CVE-2017-11134 MEDIUM
heinekingmedia StashCat < 1.7.5 - Sensitive Information Exposure via Log File
CVSS 6.5
CVE-2017-6709 CRITICAL
Cisco Ultra Services Framework < 5.0.2 - Unauthenticated Exposure of Sensitive Information via AutoVNF Log Files
CVSS 9.8
CVE-2017-9615 CRITICAL
Cognito Software Moneyworks <8.0.3 - Info Disclosure
CVSS 9.8
Details
Vulnerabilities 1,138
Exploit Likelihood Medium