VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 47 of 60
  • CVE-2019-14885MedJan 23, 2020
    risk 0.28cvss 4.3epss 0.01

    A flaw was found in the JBoss EAP Vault system in all versions before 7.2.6.GA. Confidential information of the system property's security attribute value is revealed in the JBoss EAP log file when executing a JBoss CLI 'reload' command. This flaw can lead to the exposure of…

  • CVE-2019-11273MedJul 23, 2019
    risk 0.28cvss 4.3epss 0.01

    Pivotal Container Services (PKS) versions 1.3.x prior to 1.3.7, and versions 1.4.x prior to 1.4.1, contains a vulnerable component which logs the username and password to the billing database. A remote authenticated user with access to those logs may be able to retrieve…

  • CVE-2017-1480MedJun 6, 2018
    risk 0.28cvss 4.3epss 0.02

    IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 stores potentially sensitive information in log files that could be read by a remote user. IBM X-Force ID: 128617.

  • CVE-2017-1727MedJan 4, 2018
    risk 0.28cvss 4.3epss 0.01

    IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 discloses sensitive information in error messages that could aid an attacker in further attacks against the system. IBM X-Force ID: 134869.

  • CVE-2016-8912MedFeb 1, 2017
    risk 0.28cvss 4.3epss 0.01

    IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 stores potentially sensitive information in in log files that could be read by an authenticated user.

  • CVE-2016-2928MedNov 25, 2016
    risk 0.28cvss 4.3epss 0.01

    IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to obtain sensitive information by reading error logs.

  • CVE-2026-41495MedMay 8, 2026
    risk 0.27cvss 5.3epss 0.00

    n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to version 2.47.11, when n8n-mcp runs in HTTP transport mode, incoming requests to the POST /mcp endpoint had their request metadata written to server logs…

  • CVE-2025-12996MedDec 4, 2025
    risk 0.27cvss 4.1epss 0.00

    Medtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext passwords from errors logged under certain circumstances. This issue affects CareLink Network: before December 4, 2025.

  • CVE-2025-58189MedOct 29, 2025
    risk 0.27cvss 5.3epss 0.00

    When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

  • CVE-2025-10645MedOct 7, 2025
    risk 0.27cvss 5.3epss 0.00

    The WP Reset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.05 via the WF_Licensing::log() method when debugging is enabled (default). This makes it possible for unauthenticated attackers to extract sensitive license…

  • CVE-2025-42935MedAug 12, 2025
    risk 0.27cvss 4.1epss 0.00

    The SAP NetWeaver Application Server ABAP and ABAP Platform Internet Communication Manager (ICM) permits authorized users with admin privileges and local access to log files to read sensitive information, resulting in information disclosure. This leads to high impact on the…

  • CVE-2024-7586MedJun 20, 2025
    risk 0.27cvss 4.1epss 0.00

    An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, where webhook deletion audit log preserved auth credentials.

  • CVE-2024-9621MedOct 8, 2024
    risk 0.27cvss 5.3epss 0.01

    A vulnerability was found in Quarkus CXF. Passwords and other secrets may appear in the application log in spite of the user configuring them to be hidden. This issue requires some special configuration to be vulnerable, such as SOAP logging enabled, application set client, and…

  • CVE-2024-41719MedAug 14, 2024
    risk 0.27cvss 4.2epss 0.00

    When generating QKView of BIG-IP Next instance from the BIG-IP Next Central Manager (CM), F5 iHealth credentials will be logged in the BIG-IP Central Manager logs.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2024-40636MedJul 17, 2024
    risk 0.27cvss 5.3epss 0.00

    Steeltoe is an open source project that provides a collection of libraries that helps users build production-grade cloud-native applications using externalized configuration, service discovery, distributed tracing, application management, and more. When utilizing multiple Eureka…

  • CVE-2024-0912MedJun 6, 2024
    risk 0.27cvss 4.2epss 0.00

    Under certain circumstances the Microsoft® Internet Information Server (IIS) used to host the C•CURE 9000 Web Server will log Microsoft Windows credential details within logs. There is no impact to non-web service interfaces C•CURE 9000 or prior versions

  • CVE-2023-1904MedDec 14, 2023
    risk 0.27cvss 4.2epss 0.00

    In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the configuration of Octopus Server.

  • CVE-2023-31417MedOct 26, 2023
    risk 0.27cvss 4.1epss 0.00

    Elasticsearch generally filters out sensitive information and credentials before logging to the audit log. It was found that this filtering was not applied when requests to Elasticsearch use certain deprecated URIs for APIs. The impact of this flaw is that sensitive information…

  • CVE-2021-39011MedJan 20, 2023
    risk 0.27cvss 4.2epss 0.01

    IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 stores potentially sensitive information in log files that could be read by a privileged user. IBM X-Force ID: 213645.

  • CVE-2022-27895MedNov 15, 2022
    risk 0.27cvss 4.2epss 0.00

    Information Exposure Through Log Files vulnerability discovered in Foundry when logs were captured using an underlying library known as Build2. This issue was present in versions earlier than 1.785.0. Upgrade to Build2 version 1.785.0 or greater.