Vulnerabilities > Information Exposure Through Log Files

DATE CVE VULNERABILITY TITLE RISK
2020-07-31 CVE-2020-5414 Information Exposure Through Log Files vulnerability in VMWare products
VMware Tanzu Application Service for VMs (2.7.x versions prior to 2.7.19, 2.8.x versions prior to 2.8.13, and 2.9.x versions prior to 2.9.7) contains an App Autoscaler that logs the UAA admin password.
network
low complexity
vmware CWE-532
5.7
2020-07-27 CVE-2020-4498 Information Exposure Through Log Files vulnerability in IBM MQ Appliance
IBM MQ Appliance 9.1 LTS and 9.1 CD could allow a local privileged user to obtain highly sensitve information due to inclusion of data within trace files.
local
low complexity
ibm CWE-532
4.4
2020-07-27 CVE-2020-4405 Information Exposure Through Log Files vulnerability in IBM Verify Gateway 1.0.0/1.0.1
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 could disclose potentially sensitive information to an authenticated user due to world readable log files.
network
low complexity
ibm CWE-532
4.3
2020-07-08 CVE-2020-6938 Information Exposure Through Log Files vulnerability in Tableau Server
A sensitive information disclosure vulnerability in Tableau Server 10.5, 2018.x, 2019.x, 2020.x released before June 26, 2020, could allow access to sensitive information in log files.
network
low complexity
tableau CWE-532
7.5
2020-07-07 CVE-2020-15581 Information Exposure Through Log Files vulnerability in Google Android
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software.
network
low complexity
google CWE-532
5.3
2020-07-01 CVE-2020-5908 Information Exposure Through Log Files vulnerability in F5 Big-Ip Access Policy Manager
In versions bundled with BIG-IP APM 12.1.0-12.1.5 and 11.6.1-11.6.5.2, Edge Client for Linux exposes full session ID in the local log files.
local
low complexity
f5 CWE-532
5.5
2020-07-01 CVE-2019-4706 Information Exposure Through Log Files vulnerability in IBM Security Identity Manager Virtual Appliance 7.0.2
IBM Security Identity Manager Virtual Appliance 7.0.2 writes information to log files which can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.
network
low complexity
ibm CWE-532
2.7
2020-06-19 CVE-2020-10750 Information Exposure Through Log Files vulnerability in Linuxfoundation Jaeger
Sensitive information written to a log file vulnerability was found in jaegertracing/jaeger before version 1.18.1 when the Kafka data store is used.
local
low complexity
linuxfoundation CWE-532
5.5
2020-06-19 CVE-2020-14470 Information Exposure Through Log Files vulnerability in Octopus Deploy
In Octopus Deploy 2018.8.0 through 2019.x before 2019.12.2, an authenticated user with could trigger a deployment that leaks the Helm Chart repository password.
network
low complexity
octopus CWE-532
6.5
2020-06-19 CVE-2019-20852 Information Exposure Through Log Files vulnerability in Mattermost Mobile
An issue was discovered in Mattermost Mobile Apps before 1.26.0.
network
low complexity
mattermost CWE-532
7.5