VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 46 of 60
  • CVE-2022-38756MedDec 16, 2022
    risk 0.28cvss 4.3epss 0.01

    A vulnerability has been identified in Micro Focus GroupWise Web in versions prior to 18.4.2. The GW Web component makes a request to the Post Office Agent that contains sensitive information in the query parameters that could be logged by any intervening HTTP proxies.

  • CVE-2022-31684MedOct 19, 2022
    risk 0.28cvss 4.3epss 0.01

    Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests. The logged headers may reveal valid access tokens to those with access to server logs. This may affect only invalid HTTP requests where logging at WARN level…

  • CVE-2022-31674MedAug 10, 2022
    risk 0.28cvss 4.3epss 0.01

    VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can access log files that lead to information disclosure.

  • CVE-2022-31047MedJun 14, 2022
    risk 0.28cvss 5.3epss 0.01

    TYPO3 is an open source web content management system. Prior to versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, and 11.5.11, system internal credentials or keys (e.g. database credentials) can be logged as plaintext in exception handlers, when logging the complete…

  • CVE-2022-32254MedJun 14, 2022
    risk 0.28cvss 4.3epss 0.01

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). A customized HTTP POST request could force the application to write the status of a given user to a log file, exposing sensitive user information that could provide valuable guidance to an…

  • CVE-2022-20807MedMay 27, 2022
    risk 0.28cvss 4.3epss 0.01

    Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device. For…

  • CVE-2022-20806MedMay 27, 2022
    risk 0.28cvss 4.3epss 0.01

    Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device. For…

  • CVE-2022-20809MedMay 26, 2022
    risk 0.28cvss 4.3epss 0.01

    Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device. For…

  • CVE-2022-26907MedApr 15, 2022
    risk 0.28cvss 5.3epss 0.02

    Azure SDK for .NET Information Disclosure Vulnerability

  • CVE-2021-27019MedAug 30, 2021
    risk 0.28cvss 4.3epss 0.01

    PuppetDB logging included potentially sensitive system information.

  • CVE-2021-26999MedAug 6, 2021
    risk 0.28cvss 4.3epss 0.01

    NetApp Cloud Manager versions prior to 3.9.9 log sensitive information when an Active Directory connection fails. The logged information is available only to authenticated users. Customers with auto-upgrade enabled should already be on a fixed version while customers using…

  • CVE-2021-26998MedAug 6, 2021
    risk 0.28cvss 4.3epss 0.01

    NetApp Cloud Manager versions prior to 3.9.9 log sensitive information that is available only to authenticated users. Customers with auto-upgrade enabled should already be on a fixed version while customers using on-prem connectors with auto-upgrade disabled are advised to…

  • CVE-2021-32767MedJul 20, 2021
    risk 0.28cvss 5.3epss 0.01

    TYPO3 is an open source PHP based web content management system. In versions 9.0.0 through 9.5.27, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0, user credentials may been logged as plain-text. This occurs when explicitly using log level debug, which is not the default…

  • CVE-2021-31546MedApr 22, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly logged sensitive suppression deletions, which should not have been visible to users with access to view AbuseFilter log data.

  • CVE-2021-24024MedApr 12, 2021
    risk 0.28cvss 4.3epss 0.01

    A clear text storage of sensitive information into log file vulnerability in FortiADCManager 5.3.0 and below, 5.2.1 and below and FortiADC 5.3.7 and below may allow a remote authenticated attacker to read other local users' password in log files.

  • CVE-2021-1226MedJan 13, 2021
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, Cisco Emergency Responder, and Cisco…

  • CVE-2020-11646MedOct 15, 2020
    risk 0.28cvss 4.3epss 0.01

    A log information disclosure vulnerability in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to view log information reserved for other users.

  • CVE-2020-4405MedJul 27, 2020
    risk 0.28cvss 4.3epss 0.01

    IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 could disclose potentially sensitive information to an authenticated user due to world readable log files. IBM X-Force ID: 179484.

  • CVE-2019-4286MedApr 29, 2020
    risk 0.28cvss 4.3epss 0.00

    IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 could disclose highly senstiive user information to an authenticated user with physical access to the device. IBM X-Force ID: 160514.

  • CVE-2020-1928MedJan 28, 2020
    risk 0.28cvss 5.3epss 0.04

    An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purposes. This would expose literal values entered in a sensitive property when no parameter was present.