VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 12 of 60
  • CVE-2019-18385HigOct 23, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered on TerraMaster FS-210 4.0.19 devices. An unauthenticated attacker can download log files via the include/makecvs.php?Event= substring.

  • CVE-2019-6656HigSep 25, 2019
    risk 0.49cvss 7.5epss 0.01

    BIG-IP APM Edge Client before version 7.1.8 (7180.2019.508.705) logs the full apm session ID in the log files. Vulnerable versions of the client are bundled with BIG-IP APM versions 15.0.0-15.0.1, 14,1.0-14.1.0.6, 14.0.0-14.0.0.4, 13.0.0-13.1.1.5, 12.1.0-12.1.5, and…

  • CVE-2019-0202HigJul 26, 2019
    risk 0.49cvss 7.5epss 0.02

    The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host's file system that were not intended to be accessible via these…

  • CVE-2019-13509HigJul 18, 2019
    risk 0.49cvss 7.5epss 0.04

    In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometimes add secrets to the debug log. This applies to a scenario where docker stack deploy is run to redeploy a stack that includes…

  • CVE-2019-11492HigApr 26, 2019
    risk 0.49cvss 7.5epss 0.01

    ProjectSend before r1070 writes user passwords to the server logs.

  • CVE-2019-9724HigApr 24, 2019
    risk 0.49cvss 7.5epss 0.01

    aquaverde Aquarius CMS through 4.3.5 allows Information Exposure through Log Files because of an error in the Log-File writer component.

  • CVE-2018-19513HigMar 21, 2019
    risk 0.49cvss 7.5epss 0.02

    In Webgalamb through 7.0, log files are exposed to the internet with predictable files/logs/sql_error_log/YYYY-MM-DD-sql_error_log.log filenames. The log file could contain sensitive client data (email addresses) and also facilitates exploitation of SQL injection errors.

  • CVE-2019-0741HigMar 5, 2019
    risk 0.49cvss 7.5epss 0.07

    An information disclosure vulnerability exists in the way Azure IoT Java SDK logs sensitive information, aka 'Azure IoT Java SDK Information Disclosure Vulnerability'.

  • CVE-2019-0266HigFeb 15, 2019
    risk 0.49cvss 7.5epss 0.02

    Under certain conditions SAP HANA Extended Application Services, version 1.0, advanced model (XS advanced) writes credentials of platform users to a trace file of the SAP HANA system. Even though this trace file is protected from unauthorized access, the risk of leaking…

  • CVE-2018-19865HigDec 5, 2018
    risk 0.49cvss 7.5epss 0.02

    A keystroke logging issue was discovered in Virtual Keyboard in Qt 5.7.x, 5.8.x, 5.9.x, 5.10.x, and 5.11.x before 5.11.3.

  • CVE-2018-14700HigDec 3, 2018
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the /mysql/api/logfile.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve MySQL log files via the "name" URL parameter.

  • CVE-2018-17447HigOct 23, 2018
    risk 0.49cvss 7.5epss 0.02

    An Information Exposure Through Log Files issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.

  • CVE-2018-3828HigSep 19, 2018
    risk 0.49cvss 7.5epss 0.01

    Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exception conditions would result in encryption keys, passwords, and other security sensitive headers being leaked to the allocator logs. An…

  • CVE-2018-7683HigJun 21, 2018
    risk 0.49cvss 7.5epss 0.01

    Micro Focus Solutions Business Manager versions prior to 11.4 might reveal certain sensitive information in server log files.

  • CVE-2016-10526HigMay 31, 2018
    risk 0.49cvss 8.6epss 0.02

    A common setup to deploy to gh-pages on every commit via a CI system is to expose a github token to ENV and to use it directly in the auth part of the url. In module versions < 0.9.1 the auth portion of the url is outputted as part of the grunt tasks logging function. If this…

  • CVE-2018-7433HigMar 2, 2018
    risk 0.49cvss 7.5epss 0.01

    The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page.

  • CVE-2017-15572HigOct 18, 2017
    risk 0.49cvss 7.5epss 0.02

    In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, because account/lost_password does not use a redirect.

  • CVE-2016-9344HigFeb 13, 2017
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Moxa MiiNePort E1 versions prior to 1.8, E2 versions prior to 1.4, and E3 versions prior to 1.1. An attacker may be able to brute force an active session cookie to be able to download configuration files.

  • CVE-2016-8346HigFeb 13, 2017
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Moxa EDR-810 Industrial Secure Router. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access configuration and log files (PRIVILEGE ESCALATION).

  • CVE-2015-8977HigJan 31, 2017
    risk 0.49cvss 7.5epss 0.02

    MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allow remote attackers to obtain the installation path via vectors involving error log files.