VYPR

CWE-117

Improper Output Neutralization for Logs

BaseDraftLikelihood: Medium

Description

The product constructs a log message from external input, but it does not neutralize or incorrectly neutralizes special elements when the message is written to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-268 · CAPEC-81 · CAPEC-93

CVEs mapped to this weakness (111)

page 3 of 6
  • CVE-2021-43410MedDec 9, 2021
    risk 0.35cvss 5.3epss 0.02

    Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some HTTP request parameters are logged without first being escaped. Versions affected: master branch before commit 3c5d8c7 [1] of airavata-django-portal [1]…

  • CVE-2021-20333MedJul 23, 2021
    risk 0.35cvss 5.3epss 0.01

    Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server v4.0 versions prior to 4.0.21 and MongoDB Server v4.2…

  • CVE-2019-14864MedJan 2, 2020
    risk 0.35cvss 6.5epss 0.02

    Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any…

  • CVE-2026-9016MedJun 6, 2026
    risk 0.34cvss 5.3epss 0.00

    The Debug Log Manager – Conveniently Monitor and Inspect Errors plugin for WordPress is vulnerable to Improper Output Neutralization for Logs in all versions up to, and including, 2.5.0. This is due to the `log_js_errors()` AJAX handler being registered for unauthenticated…

  • CVE-2026-5078MedJun 3, 2026
    risk 0.34cvss 5.3epss 0.00

    Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization request header and writes it to the log stream without neutralizing control characters. An unauthenticated attacker can send a crafted Authorization Basic header…

  • CVE-2026-6494MedApr 17, 2026
    risk 0.34cvss 5.3epss 0.00

    A flaw was found in the AAP MCP server. An unauthenticated remote attacker can exploit a log injection vulnerability by sending specially crafted input to the `toolsetroute` parameter. This parameter is not properly sanitized before being written to logs, allowing the attacker…

  • CVE-2025-20384MedDec 3, 2025
    risk 0.34cvss 5.3epss 0.00

    In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.4, 10.0.2503.6, and 9.3.2411.117.125, an unauthenticated attacker can inject American National Standards Institute (ANSI) escape codes into Splunk log files…

  • CVE-2025-36081MedOct 28, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Concert Software 1.0.0 through 2.0.0 could allow a user to modify system logs due to improper neutralization of log input.

  • CVE-2024-52962MedApr 8, 2025
    risk 0.34cvss 5.3epss 0.00

    An Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 and below, version 7.4.5 and below, version 7.2.8 and below, version 7.0.13 and below and FortiManager version 7.6.1 and below, version 7.4.5 and below, version 7.2.8 and below,…

  • CVE-2025-23405MedFeb 28, 2025
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated log effects metrics gathering incident response efforts and potentially exposes risk of injection attacks (ex log injection).

  • CVE-2024-49355MedFeb 20, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM OpenPages with Watson 8.3 and 9.0 may write improperly neutralized data to server log files when the tracing is enabled per the System Tracing feature.

  • CVE-2024-56473MedFeb 5, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Aspera Shares 1.9.0 through 1.10.0 PL6 could allow an attacker to spoof their IP address, which is written to log files, due to improper verification of 'Client-IP' headers.

  • CVE-2024-35150MedJan 25, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Maximo Application Suite 8.10.12, 8.11.0, 9.0.1, and 9.1.0 - Monitor Component does not neutralize output that is written to logs, which could allow an attacker to inject false log entries.

  • CVE-2024-31845MedMay 21, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using a GET query string parameter. This parameter can be modified by an attacker, so that every action he…

  • CVE-2023-28952MedMay 3, 2024
    risk 0.34cvss 5.3epss 0.00

    IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to injection attacks in application logging by not sanitizing user provided data. IBM X-Force ID: 251463.

  • CVE-2023-7234MedJan 16, 2024
    risk 0.34cvss 5.3epss 0.00

    OPCUAServerToolkit will write a log message once an OPC UA client has successfully connected containing the client's self-defined description field.

  • CVE-2023-46713MedDec 13, 2023
    risk 0.34cvss 5.3epss 0.00

    An improper output neutralization for logs in Fortinet FortiWeb 6.2.0 - 6.2.8, 6.3.0 - 6.3.23, 7.0.0 - 7.0.9, 7.2.0 - 7.2.5 and 7.4.0 may allow an attacker to forge traffic logs via a crafted URL of the web application.

  • CVE-2023-31405MedJul 11, 2023
    risk 0.34cvss 5.3epss 0.00

    SAP NetWeaver AS for Java - versions ENGINEAPI 7.50, SERVERCORE 7.50, J2EE-APPS 7.50, allows an unauthenticated attacker to craft a request over the network which can result in unwarranted modifications to a system log without user interaction. There is no ability to view any…

  • CVE-2023-0595MedFeb 24, 2023
    risk 0.34cvss 5.3epss 0.00

    A CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log files when malicious packets are sent to the Geo SCADA server's database web port (default 443). Affected products: EcoStruxure Geo SCADA Expert 2019,…

  • CVE-2022-1522MedSep 6, 2022
    risk 0.34cvss 5.3epss 0.01

    The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-117: Improper Output Neutralization for Logs, which allows an attacker to create false logs that show the password as having been changed when it is not, complicating…