VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 31 of 60
  • CVE-2020-3447MedAug 17, 2020
    risk 0.36cvss 5.5epss 0.01

    A vulnerability in the CLI of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to access sensitive information on an affected device. The vulnerability is…

  • CVE-2020-5908MedJul 1, 2020
    risk 0.36cvss 5.5epss 0.00

    In versions bundled with BIG-IP APM 12.1.0-12.1.5 and 11.6.1-11.6.5.2, Edge Client for Linux exposes full session ID in the local log files.

  • CVE-2020-1624MedApr 8, 2020
    risk 0.36cvss 5.5epss 0.00

    A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via raw objmon configuration files. This issue affects all versions of Junos OS Evolved prior to 19.1R1.

  • CVE-2020-1623MedApr 8, 2020
    risk 0.36cvss 5.5epss 0.00

    A local, authenticated user with shell can view sensitive configuration information via the ev.ops configuration file. This issue affects all versions of Junos OS Evolved prior to 19.2R1.

  • CVE-2020-1622MedApr 8, 2020
    risk 0.36cvss 5.5epss 0.00

    A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via the EvoSharedObjStore. This issue affects all versions of Junos OS Evolved prior to 19.1R1.

  • CVE-2020-1621MedApr 8, 2020
    risk 0.36cvss 5.5epss 0.00

    A local, authenticated user with shell can obtain the hashed values of login passwords via configd traces. This issue affects all versions of Junos OS Evolved prior to 19.3R1.

  • CVE-2020-1620MedApr 8, 2020
    risk 0.36cvss 5.5epss 0.00

    A local, authenticated user with shell can obtain the hashed values of login passwords via configd streamer log. This issue affects all versions of Junos OS Evolved prior to 19.3R1.

  • CVE-2020-4083MedMar 5, 2020
    risk 0.36cvss 5.5epss 0.00

    HCL Connections 6.5 is vulnerable to possible information leakage. Connections could disclose sensitive information via trace logs to a local user.

  • CVE-2020-7215MedJan 20, 2020
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Gallagher Command Centre 7.x before 7.90.991(MR5), 8.00 before 8.00.1161(MR5), and 8.10 before 8.10.1134(MR4). External system configuration data (used for third party integrations such as DVR systems) were logged in the Command Centre event trail. Any…

  • CVE-2014-3536MedDec 15, 2019
    risk 0.36cvss 5.5epss 0.00

    CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration

  • CVE-2019-19039MedNov 21, 2019
    risk 0.36cvss 5.5epss 0.01

    __btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENOENT case, which allows local users to obtain potentially sensitive information about register values via the dmesg program. NOTE: The BTRFS development team…

  • CVE-2019-16210MedNov 8, 2019
    risk 0.36cvss 5.5epss 0.00

    Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save.

  • CVE-2019-16206MedNov 8, 2019
    risk 0.36cvss 5.5epss 0.00

    The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ and the 'debug' logging level; which could allow a local authenticated attacker to access sensitive information.

  • CVE-2018-20956MedAug 8, 2019
    risk 0.36cvss 5.5epss 0.00

    Swann SWWHD-INTCAM-HD devices leave the PSK in logs after a factory reset. NOTE: all affected customers were migrated by 2020-08-31.

  • CVE-2019-10194MedJul 11, 2019
    risk 0.36cvss 5.5epss 0.00

    Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could be disclosed in log files (if playbooks are run with -v) or in playbooks stored on Metrics or Bastion hosts.

  • CVE-2019-4299MedJul 1, 2019
    risk 0.36cvss 5.5epss 0.00

    IBM Robotic Process Automation with Automation Anywhere 11 could allow a local user to obtain highly sensitive information from log files when debugging is enabled. IBM X-Force ID: 160765.

  • CVE-2019-4143MedApr 8, 2019
    risk 0.36cvss 5.5epss 0.00

    The IBM Cloud Private Key Management Service (IBM Cloud Private 3.1.1 and 3.1.2) could allow a local user to obtain sensitive from the KMS plugin container log. IBM X-Force ID: 158348.

  • CVE-2018-16889MedJan 28, 2019
    risk 0.36cvss 5.5epss 0.01

    Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.

  • CVE-2019-0004MedJan 15, 2019
    risk 0.36cvss 5.5epss 0.00

    On Juniper ATP, the API key and the device key are logged in a file readable by authenticated local users. These keys are used for performing critical operations on the WebUI interface. This issue affects Juniper ATP 5.0 versions prior to 5.0.3.

  • CVE-2018-15001MedDec 28, 2018
    risk 0.36cvss 5.5epss 0.00

    The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform app with a package name of com.vivo.bsptest (versionCode=1, versionName=1.0) containing an exported activity app component named…