VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 30 of 60
  • CVE-2022-27636MedMay 5, 2022
    risk 0.36cvss 5.5epss 0.00

    On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, as well as F5 BIG-IP APM Clients 7.x versions prior to 7.2.1.5, BIG-IP Edge Client…

  • CVE-2022-27888MedApr 26, 2022
    risk 0.36cvss 5.5epss 0.00

    Foundry Issues service versions 2.244.0 to 2.249.0 was found to be logging in a manner that captured sensitive information (session tokens). This issue was fixed in 2.249.1.

  • CVE-2022-22703MedJan 17, 2022
    risk 0.36cvss 5.5epss 0.00

    In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the log file of the .exe installer.

  • CVE-2021-44234MedJan 14, 2022
    risk 0.36cvss 5.5epss 0.00

    SAP Business One - version 10.0, extended log stores information that can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.

  • CVE-2021-39032MedJan 14, 2022
    risk 0.36cvss 5.5epss 0.00

    IBM Sterling Gentran:Server for Microsoft Windows 5.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 213962.

  • CVE-2021-45449MedJan 12, 2022
    risk 0.36cvss 5.5epss 0.00

    Docker Desktop version 4.3.0 and 4.3.1 has a bug that may log sensitive information (access token or password) on the user's machine during login. This only affects users if they are on Docker Desktop 4.3.0, 4.3.1 and the user has logged in while on 4.3.0, 4.3.1. Gaining access…

  • CVE-2021-0997MedDec 15, 2021
    risk 0.36cvss 5.5epss 0.00

    In handleUpdateNetworkState of GnssNetworkConnectivityHandler.java , there is a possible APN disclosure due to log information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-37036MedNov 23, 2021
    risk 0.36cvss 5.5epss 0.00

    There is an information leakage vulnerability in FusionCompute 6.5.1, eCNS280_TD V100R005C00 and V100R005C10. Due to the improperly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may…

  • CVE-2021-40364MedNov 9, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC04), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1), SIMATIC WinCC V15 and earlier (All versions < V15 SP1 Update 7), SIMATIC WinCC V16 (All versions < V16…

  • CVE-2020-10052MedNov 9, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12). The affected application writes sensitive data, such as usernames and passwords in log files. A local attacker with access to the log files could use this information to launch further…

  • CVE-2021-34689MedJul 15, 2021
    risk 0.36cvss 5.5epss 0.00

    iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A locally authenticated attacker can read the system's Personal Key in world-readable %PROGRAMDATA% log files.

  • CVE-2021-25423MedJun 11, 2021
    risk 0.36cvss 5.5epss 0.00

    Improper log management vulnerability in Watch Active2 PlugIn prior to 2.2.08.21033151 version allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone via log.

  • CVE-2021-25422MedJun 11, 2021
    risk 0.36cvss 5.5epss 0.00

    Improper log management vulnerability in Watch Active PlugIn prior to version 2.2.07.21033151 allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone within log.

  • CVE-2021-25421MedJun 11, 2021
    risk 0.36cvss 5.5epss 0.00

    Improper log management vulnerability in Galaxy Watch3 PlugIn prior to version 2.2.09.21033151 allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone within log.

  • CVE-2021-25420MedJun 11, 2021
    risk 0.36cvss 5.5epss 0.00

    Improper log management vulnerability in Galaxy Watch PlugIn prior to version 2.2.05.21033151 allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone within log.

  • CVE-2021-3447MedApr 1, 2021
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged in plain-text on managed nodes, as well as being made visible on the controller node when run in verbose mode. These parameters were not protected by the…

  • CVE-2021-25688MedFeb 11, 2021
    risk 0.36cvss 5.5epss 0.00

    Under certain conditions, Teradici PCoIP Agents for Windows prior to version 20.10.0 and Teradici PCoIP Agents for Linux prior to version 21.01.0 may log parts of a user's password in the application logs.

  • CVE-2020-4900MedNov 30, 2020
    risk 0.36cvss 5.5epss 0.00

    IBM Business Automation Workflow 19.0.0.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 190991.

  • CVE-2020-10762MedNov 24, 2020
    risk 0.36cvss 5.5epss 0.00

    An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes recording passwords to the cmd_history.log file which is world-readable. This flaw allows local users to obtain sensitive…

  • CVE-2020-25046MedAug 31, 2020
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The USB driver leaks address information via kernel logging. The Samsung IDs are SVE-2020-17602, SVE-2020-17603, SVE-2020-17604 (August 2020).