CWE-532
1,164 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Insertion of Sensitive Information into Log File
Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.
CVEs (1,164)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IBM PureApplication System 2.2.3.0 through 2.2.5.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 159242. |
Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials when configured to use a MySQL database. A local authenticated malicious user may read any credential...Show more |
2Netapp Redhat6Active Iq Unified Manager Jboss Data GridOpenshift Application Runtimes+3 moreJun 17, 2026 Jun 12, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR le...Show more |
Northern.tech CFEngine Enterprise 3.12.1 has Insecure Permissions. |
Sony Bravia Smart TV devices allow remote attackers to retrieve the static Wi-Fi password (used when the TV is acting as an access point) by using the Photo Sharing Plus application to execute a backdoor API command, a d...Show more |
1Lenovo 1Xclarity Administrator Jun 17, 2026 May 3, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered HTTP proxy credentials being written to a log file in clear text. This only affects LXCA when HTTP proxy credentials have been configu...Show more |
ProjectSend before r1070 writes user passwords to the server logs. |
Aquarius CMS through 4.3.5 writes POST and GET parameters (including passwords) to a log file due to an overwriting of configuration parameters under certain circumstances. |
aquaverde Aquarius CMS through 4.3.5 allows Information Exposure through Log Files because of an error in the Log-File writer component. |
2Ibm Lenovo42Bladecenter Hs22 Firmware Bladecenter Hs23 FirmwareBladecenter Hs23e Firmware+39 moreJun 17, 2026 Apr 22, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In various firmware versions of Lenovo System x, the integrated management module II (IMM2)'s first failure data capture (FFDC) includes the web server's private key in the generated log file for support. |
It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin database. A malicious user with local access to a Satellite host can use...Show more |
1Dasannetworks 1H660rm Firmware Jun 17, 2026 Apr 11, 2019 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 The Boa server configuration on DASAN H660RM devices with firmware 1.03-0022 logs POST data to the /tmp/boa-temp file, which allows logged-in users to read the credentials of administration web interface users. |
1Juniper 2Service Insight Service NowJun 17, 2026 Apr 10, 2019 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 A password management issue exists where the Organization authentication username and password were stored in plaintext in log files. A locally authenticated attacker who is able to access these stored plaintext credenti...Show more |
The IBM Cloud Private Key Management Service (IBM Cloud Private 3.1.1 and 3.1.2) could allow a local user to obtain sensitive from the KMS plugin container log. IBM X-Force ID: 158348. |
2Openstack Redhat2Ceilometer OpenstackJun 17, 2026 Mar 26, 2019 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints sensitive configuration data to log files without DEBUG logging being activated. |
2Openstack Redhat2Octavia OpenstackNov 21, 2024 Mar 26, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Se...Show more |
2Elastic Netapp2Active Iq Performance Analytics Services LogstashJun 17, 2026 Mar 25, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified as part of the Logstash configuration, the credentials for the URL coul...Show more |
In Webgalamb through 7.0, log files are exposed to the internet with predictable files/logs/sql_error_log/YYYY-MM-DD-sql_error_log.log filenames. The log file could contain sensitive client data (email addresses) and als...Show more |
An issue was discovered in SecurEnvoy SecurAccess 9.3.502. When put in Debug mode and used for RDP connections, the application stores the emergency credentials in cleartext in the logs (present in the DEBUG folder) that...Show more |
Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of unencrypted data in logs. An attacker could exploit this vulnerability to ob...Show more |