VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 5 of 60
  • CVE-2017-8001HigNov 28, 2017
    risk 0.55cvss 8.4epss 0.00

    An issue was discovered in EMC ScaleIO 2.0.1.x. In a Linux environment, one of the support scripts saves the credentials of the ScaleIO MDM user who executed the script in clear text in temporary log files. The temporary files may potentially be read by an unprivileged user with…

  • CVE-2024-30151HigMay 6, 2026
    risk 0.54cvss 8.3epss 0.00

    HCL BigFix Service Management (SX) is affected by a Broken Access Control vulnerability leading to privilege escalation. This could allow unauthorized users to gain elevated privileges, bypassing intended access restrictions. This may result in exposure of sensitive data or…

  • CVE-2018-3609HigFeb 16, 2018
    risk 0.54cvss 8.1epss 0.21

    A vulnerability in the Trend Micro InterScan Messaging Security Virtual Appliance 9.0 and 9.1 management portal could allow an unauthenticated user to access sensitive information in a particular log file that could be used to bypass authentication on vulnerable installations.

  • CVE-2026-50205HigJun 4, 2026
    risk 0.53cvss 8.2epss 0.00

    System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data.

  • CVE-2026-25193HigMay 25, 2026
    risk 0.53cvss 8.1epss 0.00

    Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure.  Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network…

  • CVE-2025-54120CriJul 23, 2025
    risk 0.53cvss epss 0.00

    PCL (Plain Craft Launcher) Community Edition is a Minecraft launcher. In PCL CE versions 2.12.0-beta.5 to 2.12.0-beta.9, the login credentials used during the third-party login process are accidentally recorded in the local log file. Although the log file is not automatically…

  • CVE-2024-20440HigSep 4, 2024
    risk 0.53cvss 7.5epss 0.52

    A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosity in a debug log file. An attacker could exploit this vulnerability by sending a crafted HTTP…

  • CVE-2024-43444HigAug 26, 2024
    risk 0.53cvss 8.2epss 0.00

    Passwords of agents and customers are displayed in plain text in the OTRS admin log module if certain configurations regarding the authentication sources match and debugging for the authentication backend has been enabled. This issue affects: * OTRS from 7.0.X through…

  • CVE-2023-46230HigJan 30, 2024
    risk 0.53cvss 8.2epss 0.00

    In Splunk Add-on Builder versions below 4.1.4, the app writes sensitive information to internal log files.

  • CVE-2023-6746HigDec 21, 2023
    risk 0.53cvss 8.1epss 0.01

    An insertion of sensitive information into log file vulnerability was identified in the log files for a GitHub Enterprise Server back-end service that could permit an `adversary in the middle attack` when combined with other phishing techniques. To exploit this, an attacker…

  • CVE-2023-46667HigOct 26, 2023
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in Fleet Server >= v8.10.0 and < v8.10.3 where Agent enrolment tokens are being inserted into the Fleet Server’s log file in plain text. These enrolment tokens could allow someone to enrol an agent into an agent policy, and potentially use that to…

  • CVE-2023-43261HigOct 4, 2023
    risk 0.53cvss 7.5epss 0.59

    An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.

  • CVE-2023-3350HigOct 3, 2023
    risk 0.53cvss 8.2epss 0.00

    A Cryptographic Issue vulnerability has been found on IBERMATICA RPS, affecting version 2019. By firstly downloading the log file, an attacker could retrieve the SQL query sent to the application in plaint text. This log file contains the password hashes coded with AES-CBC-128…

  • CVE-2023-3349HigOct 3, 2023
    risk 0.53cvss 8.2epss 0.00

    Information exposure vulnerability in IBERMATICA RPS 2019, which exploitation could allow an unauthenticated user to retrieve sensitive information, such as usernames, IP addresses or SQL queries sent to the application. By accessing the URL /RPS2019Service/status.html, the…

  • CVE-2023-22574HigFeb 1, 2023
    risk 0.53cvss 8.1epss 0.01

    Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in platform API of IPMI module. A low-privileged user with permission to read logs on the cluster could potentially exploit this vulnerability, leading to…

  • CVE-2022-34369HigSep 2, 2022
    risk 0.53cvss 8.1epss 0.01

    Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3 , contain an insertion of sensitive information in log files vulnerability. A remote unprivileged attacker could potentially exploit this vulnerability, leading to exposure of this…

  • CVE-2021-45103HigApr 6, 2022
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker can access files stored in S3 cloud storage that a user has asked HTCondor to transfer.

  • CVE-2021-36278HigAug 16, 2021
    risk 0.53cvss 8.1epss 0.01

    Dell EMC PowerScale OneFS versions 8.2.x, 9.1.0.x, and 9.1.1.1 contain a sensitive information exposure vulnerability in log files. A local malicious user with ISI_PRIV_LOGIN_SSH, ISI_PRIV_LOGIN_CONSOLE, or ISI_PRIV_SYS_SUPPORT privileges may exploit this vulnerability to access…

  • CVE-2021-21558HigJun 8, 2021
    risk 0.53cvss 8.2epss 0.00

    Dell EMC NetWorker, 18.x, 19.1.x, 19.2.x 19.3.x, 19.4 and 19.4.0.1, contains an Information Disclosure vulnerability. A local administrator of the gstd system may potentially exploit this vulnerability to read LDAP credentials from local logs and use the stolen credentials to…

  • CVE-2019-11336HigMay 14, 2019
    risk 0.53cvss 8.1epss 0.03

    Sony Bravia Smart TV devices allow remote attackers to retrieve the static Wi-Fi password (used when the TV is acting as an access point) by using the Photo Sharing Plus application to execute a backdoor API command, a different vulnerability than CVE-2019-10886.