VYPR

CWE-1323

Improper Management of Sensitive Trace Data

BaseDraft

Description

Trace data collected from several sources on the System-on-Chip (SoC) is stored in unprotected locations or transported to untrusted agents.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-150 · CAPEC-167 · CAPEC-545

CVEs mapped to this weakness (2)

  • CVE-2024-54173MedFeb 28, 2025
    risk 0.31cvss 4.7epss 0.00

    IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD reveals potentially sensitive information in trace files that could be read by a local user when webconsole trace is enabled.

  • CVE-2024-49338MedJan 18, 2025
    risk 0.29cvss 4.4epss 0.00

    IBM App Connect Enterprise 12.0.1.0 through 12.0.7.0and 13.0.1.0 under certain configurations could allow a privileged user to obtain JMS credentials.