VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 23 of 60
  • CVE-2025-6624HigJun 26, 2025
    risk 0.40cvss 7.2epss 0.00

    Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through local Snyk CLI debug logs. Container Registry credentials provided via environment variables or command line arguments can be exposed when executing Snyk CLI…

  • CVE-2025-36050MedJun 19, 2025
    risk 0.40cvss 6.2epss 0.00

    IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 stores potentially sensitive information in log files that could be read by a local user.

  • CVE-2024-45091MedJan 21, 2025
    risk 0.40cvss 6.2epss 0.00

    IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.24, 7.1 through 7.1.2.10, and 7.2 through 7.2.3.13 stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs.

  • CVE-2024-42196MedDec 6, 2024
    risk 0.40cvss 6.2epss 0.00

    HCL Launch stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs.

  • CVE-2024-27154MedJun 14, 2024
    risk 0.40cvss 6.2epss 0.00

    Passwords are stored in clear-text logs. An attacker can retrieve passwords. As for the affected products/models/versions, see the reference URL.

  • CVE-2023-40694MedMay 7, 2024
    risk 0.40cvss 6.2epss 0.00

    IBM Watson CP4D Data Stores 4.0.0 through 4.8.4 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 264838.

  • CVE-2024-25030MedApr 3, 2024
    risk 0.40cvss 6.2epss 0.00

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 281677.

  • CVE-2024-22464MedFeb 8, 2024
    risk 0.40cvss 6.2epss 0.01

    Dell EMC AppSync, versions from 4.2.0.0 to 4.6.0.0 including all Service Pack releases, contain an exposure of sensitive information vulnerability in AppSync server logs. A high privileged remote attacker could potentially exploit this vulnerability, leading to the disclosure…

  • CVE-2023-25682MedNov 22, 2023
    risk 0.40cvss 6.2epss 0.00

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 247034.

  • CVE-2022-43923MedFeb 24, 2023
    risk 0.40cvss 6.2epss 0.00

    IBM Maximo Application Suite 8.8.0 and 8.9.0 stores potentially sensitive information that could be read by a local user. IBM X-Force ID: 241584.

  • CVE-2022-43930MedFeb 17, 2023
    risk 0.40cvss 6.2epss 0.00

    IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to an Information Disclosure as sensitive information may be included in a log file. IBM X-Force ID: 241677.

  • CVE-2022-45098MedFeb 1, 2023
    risk 0.40cvss 6.1epss 0.00

    Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component. An authenticated local attacker could potentially exploit this vulnerability, leading to information disclosure.

  • CVE-2021-22929MedAug 31, 2021
    risk 0.40cvss 6.1epss 0.00

    An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that included timestamps of connections to V2 onion domains in tor.log.

  • CVE-2021-20536MedApr 26, 2021
    risk 0.40cvss 6.2epss 0.00

    IBM Spectrum Protect Plus File Systems Agent 10.1.6 and 10.1.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 198836.

  • CVE-2021-22184MedMar 26, 2021
    risk 0.40cvss 6.2epss 0.00

    An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to see sensitive information that wasn't properly redacted.

  • CVE-2020-6224MedApr 14, 2020
    risk 0.40cvss 6.2epss 0.01

    SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges to access user sensitive data such as passwords in trace files, when the user logs in and sends request with login credentials, leading to…

  • CVE-2018-1876MedNov 2, 2018
    risk 0.40cvss 6.2epss 0.00

    IBM Robotic Process Automation with Automation Anywhere 11 could under certain cases, display the password in a Control Room log file after installation. IBM X-Force ID: 151707.

  • CVE-2017-5137MedFeb 5, 2017
    risk 0.40cvss 6.2epss 0.01

    An issue was discovered on SendQuick Entera and Avera devices before 2HF16. An attacker could request and download the SMS logs from an unauthenticated perspective.

  • CVE-2025-66910MedDec 19, 2025
    risk 0.39cvss 6.0epss 0.00

    Turms Server v0.10.0-SNAPSHOT and earlier contains a plaintext password storage vulnerability in the administrator authentication system. The BaseAdminService class caches administrator passwords in plaintext within AdminInfo objects to optimize authentication performance. Upon…

  • CVE-2025-2002MedMar 12, 2025
    risk 0.39cvss 6.0epss 0.00

    CWE-532: Insertion of Sensitive Information into Log Files vulnerability exists that could cause the disclosure of FTP server credentials when the FTP server is deployed, and the device is placed in debug mode by an administrative user and the debug files are exported from the…