Skip to main content

CWE archive

CWE-532 CVEs

Programmatic archive

1,163 CVEs tagged with CWE-53256 Critical, 259 High, 703 Medium, 145 Low, 0 Unrated.

CVE-2019-0380

Published Oct 8, 2019

Under certain conditions, SAP Landscape Management enterprise edition, before version 3.0, allows custom secure parameters’ default values to be part of the application logs leadi…

CVSS 4.9 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2019-10212

Published Oct 2, 2019

A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials f…

CVSS 9.8 · Critical

CVE-2019-16116

Published Oct 2, 2019

EnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file. This allows an attacker to obtain the administrator passwo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9277

Published Sep 27, 2019

In the proc filesystem, there is a possible information disclosure due to log information disclosure. This could lead to local disclosure of app and browser activity with User exe…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-5532

Published Sep 18, 2019

VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability due to the logging of credentials in p…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-11465

Published Sep 10, 2019

An issue was discovered in Couchbase Server 5.5.x through 5.5.3 and 6.0.0. The Memcached "connections" stat block command emits a non-redacted username. The system information sub…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11549

Published Sep 9, 2019

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an infor…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15294

Published Aug 28, 2019

An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2). Upon an upgrade, if a custom service account is in use and the visitor management service is instal…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-15508

Published Aug 23, 2019

In Octopus Tentacle versions 3.0.8 to 5.0.0, when a web request proxy is configured, an authenticated user (in certain limited OctopusPrintVariables circumstances) could trigger a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15507

Published Aug 23, 2019

In Octopus Deploy versions 2018.8.4 to 2019.7.6, when a web request proxy is configured, an authenticated user (in certain limited special-characters circumstances) could trigger…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5634

Published Aug 22, 2019

An inclusion of sensitive information in log files vulnerability is present in Hickory Smart for Android mobile devices from Belwith Products, LLC. Communications to the internet…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10370

Published Aug 7, 2019

Jenkins Mask Passwords Plugin 2.12.0 and earlier transmits globally configured passwords in plain text as part of the configuration form, potentially resulting in their exposure.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10367

Published Aug 7, 2019

Due to an incomplete fix of CVE-2019-10343, Jenkins Configuration as Code Plugin 1.26 and earlier did not properly apply masking to some values expected to be hidden when logging…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4284

Published Aug 5, 2019

IBM Cloud Private 2.1.0 , 3.1.0, 3.1.1, and 3.1.2 could allow a local privileged user to obtain sensitive OIDC token that is printed to log files, which could be used to log in to…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18426

Published Aug 2, 2019

cPanel before 66.0.2 allows resellers to read other accounts' domain log files (SEC-288).

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2017-18423

Published Aug 2, 2019

In cPanel before 66.0.2, domain log files become readable after log processing (SEC-273).

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort
Showing 976-1,000 of 1,163 CVEsPage 40 of 47