VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,196)

page 53 of 60
  • CVE-2022-33688LowJul 12, 2022
    risk 0.21cvss 3.3epss 0.00

    Sensitive information exposure vulnerability in EventType in SecTelephonyProvider prior to SMR Jul-2022 Release 1 allows local attackers with log access permission to get IMSI through device log.

  • CVE-2022-33687LowJul 12, 2022
    risk 0.21cvss 3.3epss 0.00

    Exposure of Sensitive Information in telephony-common.jar prior to SMR Jul-2022 Release 1 allows local attackers to access IMSI via log.

  • CVE-2022-30742LowJun 7, 2022
    risk 0.21cvss 3.3epss 0.00

    Sensitive information exposure vulnerability in FmmExtraOperation of Find My Mobile prior to 7.2.24.12 allows local attackers with log access permissio to get sim card information through device log.

  • CVE-2022-30741LowJun 7, 2022
    risk 0.21cvss 3.3epss 0.00

    Sensitive information exposure vulnerability in SimChangeAlertManger of Find My Mobile prior to 7.2.24.12 allows local attackers with log access permission to get sim card information through device log.

  • CVE-2021-39739LowMar 30, 2022
    risk 0.21cvss 3.3epss 0.00

    In ArrayMap, there is a possible leak of the content of SMS messages due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-0652LowMar 22, 2022
    risk 0.21cvss 3.3epss 0.00

    Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to attempt off-line brute-force attacks against these password hashes in Sophos UTM before version 9.710.

  • CVE-2022-0021LowFeb 10, 2022
    risk 0.21cvss 3.3epss 0.00

    An information exposure through log file vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that logs the cleartext credentials of the connecting GlobalProtect user when authenticating using Connect Before Logon feature. This issue impacts GlobalProtect…

  • CVE-2022-0338MedJan 25, 2022
    risk 0.21cvss 4.3epss 0.01

    Insertion of Sensitive Information into Log File in Conda loguru prior to 0.5.3.

  • CVE-2021-26908LowApr 23, 2021
    risk 0.21cvss 3.3epss 0.00

    Automox Agent prior to version 31 logs potentially sensitive information in local log files, which could be used by a locally-authenticated attacker to subvert an organization's security program. The issue has since been fixed in version 31 of the Automox Agent.

  • CVE-2020-2048LowNov 12, 2020
    risk 0.21cvss 3.3epss 0.00

    An information exposure through log file vulnerability exists where the password for the configured system proxy server for a PAN-OS appliance may be displayed in cleartext when using the CLI in Palo Alto Networks PAN-OS software. This issue impacts: PAN-OS 8.1 versions earlier…

  • CVE-2019-20625LowMar 24, 2020
    risk 0.21cvss 3.3epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.1) and O(8.x) (Exynos chipsets) software. The ion debugfs driver allows information disclosure. The Samsung ID is SVE-2018-13427 (February 2019).

  • CVE-2019-9277LowSep 27, 2019
    risk 0.21cvss 3.3epss 0.00

    In the proc filesystem, there is a possible information disclosure due to log information disclosure. This could lead to local disclosure of app and browser activity with User execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions:…

  • CVE-2017-18423LowAug 2, 2019
    risk 0.21cvss 3.3epss 0.00

    In cPanel before 66.0.2, domain log files become readable after log processing (SEC-273).

  • CVE-2019-4296LowJul 1, 2019
    risk 0.21cvss 3.3epss 0.00

    IBM Robotic Process Automation with Automation Anywhere 11 information disclosure could allow a local user to obtain e-mail contents from the client debug log file. IBM X-Force ID: 160759.

  • CVE-2018-10889MedJul 10, 2018
    risk 0.21cvss 4.3epss 0.02

    A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details of other users who interacted with the requester.

  • CVE-2017-9271LowMar 1, 2018
    risk 0.21cvss 3.3epss 0.00

    The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used.

  • CVE-2018-5693LowJan 14, 2018
    risk 0.21cvss 3.3epss 0.00

    The LinuxMagic MagicSpam extension before 2.0.14-1 for Plesk allows local users to discover mailbox names by reading /var/log/magicspam/mslog.

  • CVE-2016-0296LowFeb 1, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) stores potentially sensitive information in log files that could be available to a local user.

  • CVE-2016-5432LowOct 3, 2016
    risk 0.21cvss 3.3epss 0.00

    The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files.

  • CVE-2025-53885MedJul 15, 2025
    risk 0.20cvss 4.2epss 0.00

    Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus Flows to handle CRUD events for users it is possible to log the incoming data to console using the "Log to Console"…