← Back
CWE-532

1,164 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Insertion of Sensitive Information into Log File

Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.

JSON object

Loading...

CVEs (1,164)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Pureapplication System
Jun 17, 2026
Jun 26, 2019
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
IBM PureApplication System 2.2.3.0 through 2.2.5.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 159242.
1Cloud Foundry
1Bosh
Jun 17, 2026
Jun 19, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials when configured to use a MySQL database. A local authenticated malicious user may read any credential...Show more
Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials when configured to use a MySQL database. A local authenticated malicious user may read any credentials that are contained in a BOSH manifest.Show less
2Netapp
Redhat
6Active Iq Unified Manager
Jboss Data GridOpenshift Application Runtimes+3 more
Jun 17, 2026
Jun 12, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR le...Show more
A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)Show less
1Northern
1Cfengine
Jun 17, 2026
Jun 6, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Northern.tech CFEngine Enterprise 3.12.1 has Insecure Permissions.
1Sony
1Photo Sharing Plus
Jun 17, 2026
May 14, 2019
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Sony Bravia Smart TV devices allow remote attackers to retrieve the static Wi-Fi password (used when the TV is acting as an access point) by using the Photo Sharing Plus application to execute a backdoor API command, a d...Show more
Sony Bravia Smart TV devices allow remote attackers to retrieve the static Wi-Fi password (used when the TV is acting as an access point) by using the Photo Sharing Plus application to execute a backdoor API command, a different vulnerability than CVE-2019-10886.Show less
1Lenovo
1Xclarity Administrator
Jun 17, 2026
May 3, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered HTTP proxy credentials being written to a log file in clear text. This only affects LXCA when HTTP proxy credentials have been configu...Show more
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered HTTP proxy credentials being written to a log file in clear text. This only affects LXCA when HTTP proxy credentials have been configured. This affects LXCA versions 2.0.0 to 2.3.x.Show less
1Projectsend
1Projectsend
Jun 17, 2026
Apr 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ProjectSend before r1070 writes user passwords to the server logs.
1Aquaverde
1Aquarius Cms
Jun 17, 2026
Apr 24, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Aquarius CMS through 4.3.5 writes POST and GET parameters (including passwords) to a log file due to an overwriting of configuration parameters under certain circumstances.
1Aquaverde
1Aquarius Cms
Jun 17, 2026
Apr 24, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
aquaverde Aquarius CMS through 4.3.5 allows Information Exposure through Log Files because of an error in the Log-File writer component.
2Ibm
Lenovo
42Bladecenter Hs22 Firmware
Bladecenter Hs23 FirmwareBladecenter Hs23e Firmware+39 more
Jun 17, 2026
Apr 22, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In various firmware versions of Lenovo System x, the integrated management module II (IMM2)'s first failure data capture (FFDC) includes the web server's private key in the generated log file for support.
1Redhat
1Satellite
Jun 17, 2026
Apr 15, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin database. A malicious user with local access to a Satellite host can use...Show more
It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin database. A malicious user with local access to a Satellite host can use those credentials to modify the database and prevent Satellite from fetching package updates, thus preventing all Satellite hosts from accessing those updates.Show less
1Dasannetworks
1H660rm Firmware
Jun 17, 2026
Apr 11, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
The Boa server configuration on DASAN H660RM devices with firmware 1.03-0022 logs POST data to the /tmp/boa-temp file, which allows logged-in users to read the credentials of administration web interface users.
1Juniper
2Service Insight
Service Now
Jun 17, 2026
Apr 10, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
A password management issue exists where the Organization authentication username and password were stored in plaintext in log files. A locally authenticated attacker who is able to access these stored plaintext credenti...Show more
A password management issue exists where the Organization authentication username and password were stored in plaintext in log files. A locally authenticated attacker who is able to access these stored plaintext credentials can use them to login to the Organization. Affected products are: Juniper Networks Service Insight versions from 15.1R1, prior to 18.1R1. Service Now versions from 15.1R1, prior to 18.1R1.Show less
1Ibm
1Cloud Private
Jun 17, 2026
Apr 8, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The IBM Cloud Private Key Management Service (IBM Cloud Private 3.1.1 and 3.1.2) could allow a local user to obtain sensitive from the KMS plugin container log. IBM X-Force ID: 158348.
2Openstack
Redhat
2Ceilometer
Openstack
Jun 17, 2026
Mar 26, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints sensitive configuration data to log files without DEBUG logging being activated.
2Openstack
Redhat
2Octavia
Openstack
Nov 21, 2024
Mar 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Se...Show more
In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.Show less
2Elastic
Netapp
2Active Iq Performance Analytics Services
Logstash
Jun 17, 2026
Mar 25, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified as part of the Logstash configuration, the credentials for the URL coul...Show more
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified as part of the Logstash configuration, the credentials for the URL could be inadvertently logged as part of the error message.Show less
1Ens
1Webgalamb
Nov 21, 2024
Mar 21, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Webgalamb through 7.0, log files are exposed to the internet with predictable files/logs/sql_error_log/YYYY-MM-DD-sql_error_log.log filenames. The log file could contain sensitive client data (email addresses) and als...Show more
In Webgalamb through 7.0, log files are exposed to the internet with predictable files/logs/sql_error_log/YYYY-MM-DD-sql_error_log.log filenames. The log file could contain sensitive client data (email addresses) and also facilitates exploitation of SQL injection errors.Show less
1Securenvoy
1Securaccess
May 30, 2025
Mar 21, 2019
N/A· v4
7.0 HIGH· v3
1.9 LOW· v2
An issue was discovered in SecurEnvoy SecurAccess 9.3.502. When put in Debug mode and used for RDP connections, the application stores the emergency credentials in cleartext in the logs (present in the DEBUG folder) that...Show more
An issue was discovered in SecurEnvoy SecurAccess 9.3.502. When put in Debug mode and used for RDP connections, the application stores the emergency credentials in cleartext in the logs (present in the DEBUG folder) that can be accessed by anyone. NOTE: The vendor disputes this as a vulnerability since the disclosure of a local account password (actually an alpha numeric passcode) is achievable only when a custom registry key is added to the windows registry. This action requires administrator access and the registry key is only provided by support staff at securenvoy to troubleshoot customer issues.Show less
1Envoy
1Passport
Nov 21, 2024
Mar 21, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of unencrypted data in logs. An attacker could exploit this vulnerability to ob...Show more
Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of unencrypted data in logs. An attacker could exploit this vulnerability to obtain two API keys, a token and other sensitive information.Show less