CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,138 vulnerabilities with CWE-532
CVE-2017-3744 MEDIUM
Lenovo IMM2 Firmware < 4.9 - Sensitive Information Disclosure in FFDC Service Log
CVSS 6.5
CVE-2017-4955 CRITICAL
Pivotal PCF Elastic Runtime <1.6.65-<1.9.5 - Info Disclosure
CVSS 9.8
CVE-2017-8075 CRITICAL
TP-Link TL-SG108E Firmware 1.1.2 Build 20141017 Rel.50749 - Cleartext Password Exposure in Log Files
CVSS 9.8
CVE-2017-8074 CRITICAL
TP-Link TL-SG108E Firmware 1.1.2 Build 20141017 Rel.50749 - Sensitive Information Exposure in Log Files
CVSS 9.8
CVE-2017-7214 CRITICAL
OpenStack Nova <15.0.1 - Info Disclosure
CVSS 9.8
CVE-2017-5153 HIGH
OSIsoft PI Coresight <2016 R2 - Info Disclosure
CVSS 7.8
CVE-2017-5549 MEDIUM
Linux Kernel < 4.9.4 - Information Disclosure via Uninitialized Memory in kl5kusb105 Driver
CVSS 5.5
CVE-2017-5137 MEDIUM
SendQuick Entera/Avera <2HF16 - Info Disclosure
CVSS 6.2
CVE-2016-10819 MEDIUM
cPanel 11.50.0.4-11.50.6.2 - Sensitive Information Exposure via Log File Rotation
CVSS 6.5
CVE-2016-10526 HIGH
grunt-gh-pages < 0.9.1 - Unauthenticated Credential Exposure via Logging Function
CVSS 8.6
CVE-2016-0898 CRITICAL
MySQL for PCF tiles <1.7.10 - Info Disclosure
CVSS 10.0
CVE-2016-10362 MEDIUM
Logstash < 5.0.1 - Sensitive Information Exposure via Elasticsearch Output Plugin
CVSS 6.5
CVE-2016-6799 HIGH
Apache Cordova Android < 5.2.2 - Sensitive Information Exposure via Log File Insertion
CVSS 7.5
CVE-2016-9985 MEDIUM
IBM Cognos Business Intelligence 10.1.1 and 10.2 - Sensitive Information Exposure in Log Files
CVSS 5.5
CVE-2016-8233 CRITICAL
Lenovo XClarity Administrator <1.2.2 - Info Disclosure
CVSS 9.8
CVE-2016-9344 HIGH
Moxa MiiNePort E1 < 1.8, E2 < 1.4, E3 < 1.1 - Unauthenticated Session Cookie Brute Force
CVSS 7.5
CVE-2016-8346 HIGH
Moxa EDR-810 - Privilege Escalation
CVSS 7.5
CVE-2016-8912 MEDIUM
IBM Kenexa LMS on Cloud <13.2.4 - Info Disclosure
CVSS 4.3
CVE-2016-0296 LOW
IBM Tivoli Endpoint Manager - Info Disclosure
CVSS 3.3
CVE-2016-9882 HIGH
Cloud Foundry Foundation cf-release < v250 and CAPI-release < v1.12.0 - Sensitive Information Exposure in Log Files
CVSS 7.5
CVE-2016-4443 MEDIUM
Red Hat Enterprise Virtualization (RHEV) Manager 3.6 - Info Disclosure
CVSS 5.5
CVE-2016-2943 LOW
IBM BigFix Remote Control < 9.1.2 - Sensitive Information Exposure via Log File
CVSS 1.9
CVE-2016-2928 MEDIUM
IBM BigFix Remote Control < 9.1.2 - Authenticated Sensitive Information Exposure via Error Logs
CVSS 4.3
CVE-2016-5967 MEDIUM
IBM Rational Asset Analyzer <6.1.0 - Info Disclosure
CVSS 5.5
CVE-2016-5432 LOW
Red Hat Enterprise Virtualization Engine 4.0 - Sensitive Information Exposure via Log File
CVSS 3.3
Details
Vulnerabilities 1,138
Exploit Likelihood Medium