← Back
CWE-532

1,220 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Insertion of Sensitive Information into Log File

Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.

JSON object

Loading...

CVEs (1,220)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Osisoft
2Pi Coresight
Pi Web Api
May 13, 2026
Feb 13, 2017
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
An issue was discovered in OSIsoft PI Coresight 2016 R2 and earlier versions, and PI Web API 2016 R2 when deployed using the PI AF Services 2016 R2 integrated install kit. An information exposure through server log files...Show more
An issue was discovered in OSIsoft PI Coresight 2016 R2 and earlier versions, and PI Web API 2016 R2 when deployed using the PI AF Services 2016 R2 integrated install kit. An information exposure through server log files vulnerability has been identified, which may allow service account passwords to become exposed for the affected services, potentially leading to unauthorized shutdown of the affected PI services as well as potential reuse of domain credentials.Show less
1Moxa
3Miineport E1 Firmware
Miineport E2 FirmwareMiineport E3 Firmware
May 13, 2026
Feb 13, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Moxa MiiNePort E1 versions prior to 1.8, E2 versions prior to 1.4, and E3 versions prior to 1.1. An attacker may be able to brute force an active session cookie to be able to download configura...Show more
An issue was discovered in Moxa MiiNePort E1 versions prior to 1.8, E2 versions prior to 1.4, and E3 versions prior to 1.1. An attacker may be able to brute force an active session cookie to be able to download configuration files.Show less
1Moxa
1Edr 810 Firmware
May 13, 2026
Feb 13, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Moxa EDR-810 Industrial Secure Router. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access configuration and log files (PRIVILEGE ESCALA...Show more
An issue was discovered in Moxa EDR-810 Industrial Secure Router. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access configuration and log files (PRIVILEGE ESCALATION).Show less
1Linux
1Linux Kernel
May 13, 2026
Feb 6, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The klsi_105_get_line_state function in drivers/usb/serial/kl5kusb105.c in the Linux kernel before 4.9.5 places uninitialized heap-memory contents into a log entry upon a failure to read the line status, which allows loc...Show more
The klsi_105_get_line_state function in drivers/usb/serial/kl5kusb105.c in the Linux kernel before 4.9.5 places uninitialized heap-memory contents into a log entry upon a failure to read the line status, which allows local users to obtain sensitive information by reading the log.Show less
1Sendquick
2Avera Sms Gateway Firmware
Entera Sms Gateway Firmware
May 13, 2026
Feb 5, 2017
N/A· v4
6.2 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered on SendQuick Entera and Avera devices before 2HF16. An attacker could request and download the SMS logs from an unauthenticated perspective.
1Ibm
1Kenexa Lms On Cloud
May 13, 2026
Feb 1, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 stores potentially sensitive information in in log files that could be read by an authenticated user.
1Ibm
1Bigfix Platform
May 13, 2026
Feb 1, 2017
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) stores potentially sensitive information in log files that could be available to a local user.
1Mybb
2Merge System
Mybb
May 13, 2026
Jan 31, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allow remote attackers to obtain the installation path via vectors involving error log files.
1Cloudfoundry
2Capi Release
Cf Release
May 13, 2026
Jan 13, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v250 and CAPI-release versions prior to v1.12.0. Cloud Foundry logs the credentials returned from service brokers in Cloud Controller syste...Show more
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v250 and CAPI-release versions prior to v1.12.0. Cloud Foundry logs the credentials returned from service brokers in Cloud Controller system component logs. These logs are written to disk and often sent to a log aggregator via syslog.Show less
1Redhat
1Enterprise Virtualization
May 6, 2026
Dec 14, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the engine-setup log file.
1Ibm
1Bigfix Remote Control
May 6, 2026
Nov 30, 2016
N/A· v4
1.9 LOW· v3
1.9 LOW· v2
IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by leveraging unspecified privileges to read a log file.
1Ibm
1Bigfix Remote Control
May 6, 2026
Nov 25, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to obtain sensitive information by reading error logs.
1Ibm
1Rational Asset Analyzer
May 6, 2026
Nov 25, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The installation component in IBM Rational Asset Analyzer (RAA) 6.1.0 before FP10 allows local users to discover the WAS Admin password by reading IM native logs.
1Redhat
1Enterprise Virtualization
May 6, 2026
Oct 3, 2016
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files.
1Moxa
1Edr G903 Firmware
May 6, 2026
May 31, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Moxa Secure Router EDR-G903 devices before 3.4.12 do not delete copies of configuration and log files after completing the import function, which allows remote attackers to obtain sensitive information by requesting thes...Show more
Moxa Secure Router EDR-G903 devices before 3.4.12 do not delete copies of configuration and log files after completing the import function, which allows remote attackers to obtain sensitive information by requesting these files at an unspecified URL.Show less
1Moxa
1Edr G903 Firmware
May 6, 2026
May 31, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to read configuration and log files via a crafted URL.
1Openstack
1Ceilometer
Apr 29, 2026
Nov 23, 2013
N/A· v4
N/A· v3
1.9 LOW· v2
(1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 and earlier, when the logging level is set to INFO, logs the connection string from ceilometer.conf, which allows local users to obtain sensitive inf...Show more
(1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 and earlier, when the logging level is set to INFO, logs the connection string from ceilometer.conf, which allows local users to obtain sensitive information (the DB2 or MongoDB password) by reading the log file.Show less
2Digital Alert Systems
Monroe Electronics
2Dasdec Eas
R189 One Net Eas
Jun 2, 2026
Jun 30, 2013
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The web server on the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 allows remote attackers to obtain sensitive configuration and status information...Show more
The web server on the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 allows remote attackers to obtain sensitive configuration and status information by reading log files.Show less
2Fedoraproject
Gnome
2Fedora
Networkmanager
Apr 29, 2026
Jun 14, 2011
N/A· v4
N/A· v3
2.1 LOW· v2
The destroy_one_secret function in nm-setting-vpn.c in libnm-util in the NetworkManager package 0.8.999-3.git20110526 in Fedora 15 creates a log entry containing a certificate password, which allows local users to obtain...Show more
The destroy_one_secret function in nm-setting-vpn.c in libnm-util in the NetworkManager package 0.8.999-3.git20110526 in Fedora 15 creates a log entry containing a certificate password, which allows local users to obtain sensitive information by reading a log file.Show less
1Apache
1Http Server
Apr 16, 2026
Dec 31, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allow remote attackers to hide HTTP requests and spoof source IP addresses...Show more
The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allow remote attackers to hide HTTP requests and spoof source IP addresses when logs are viewed with UNIX programs such as cat, tail, and grep.Show less