Vulnerabilities > Information Exposure Through Log Files

DATE CVE VULNERABILITY TITLE RISK
2020-01-27 CVE-2018-20105 Information Exposure Through Log Files vulnerability in multiple products
A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file.
local
low complexity
yast2-rmt-project opensuse suse CWE-532
5.5
2020-01-24 CVE-2020-5225 Information Exposure Through Log Files vulnerability in Simplesamlphp
Log injection in SimpleSAMLphp before version 1.18.4.
network
low complexity
simplesamlphp CWE-532
5.4
2020-01-23 CVE-2019-14885 Information Exposure Through Log Files vulnerability in Redhat products
A flaw was found in the JBoss EAP Vault system in all versions before 7.2.6.GA.
network
low complexity
redhat CWE-532
4.3
2020-01-20 CVE-2020-7215 Information Exposure Through Log Files vulnerability in Gallagher Command Centre
An issue was discovered in Gallagher Command Centre 7.x before 7.90.991(MR5), 8.00 before 8.00.1161(MR5), and 8.10 before 8.10.1134(MR4).
local
low complexity
gallagher CWE-532
5.5
2020-01-15 CVE-2019-18244 Information Exposure Through Log Files vulnerability in Osisoft PI Vision 2017/2019
In OSIsoft PI System multiple products and versions, a local attacker could view sensitive information in log files when service accounts are customized during installation or upgrade of PI Vision.
local
high complexity
osisoft CWE-532
4.7
2020-01-09 CVE-2019-11292 Information Exposure Through Log Files vulnerability in Pivotal Software Operations Manager
Pivotal Ops Manager, versions 2.4.x prior to 2.4.27, 2.5.x prior to 2.5.24, 2.6.x prior to 2.6.16, and 2.7.x prior to 2.7.5, logs all query parameters to tomcat’s access file.
network
low complexity
pivotal-software CWE-532
6.5
2019-12-23 CVE-2019-3429 Information Exposure Through Log Files vulnerability in ZTE Zxcloud Goldendata VAP Zxivsvapportalxzgav4.01.01.02
All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have a file reading vulnerability.
network
low complexity
zte CWE-532
5.3
2019-12-23 CVE-2019-19150 Information Exposure Through Log Files vulnerability in F5 Big-Ip Access Policy Manager
On versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, the BIG-IP APM system logs the client-session-id when a per-session policy is attached to the virtual server with debug logging enabled.
network
low complexity
f5 CWE-532
4.9
2019-12-17 CVE-2019-15235 Information Exposure Through Log Files vulnerability in Control-Webpanel Webpanel 0.9.8.856/0.9.8.864
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.864 allows an attacker to get a victim's session file name from /home/[USERNAME]/tmp/session/sess_xxxxxx, and the victim's token value from /usr/local/cwpsrv/logs/access_log, then use them to gain access to the victim's password (for the OS and phpMyAdmin) via an attacker account.
network
low complexity
control-webpanel CWE-532
6.5
2019-12-17 CVE-2019-14782 Information Exposure Through Log Files vulnerability in Control-Webpanel Webpanel 0.9.8.856/0.9.8.864
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.856 through 0.9.8.864 allows an attacker to get a victim's session file name from the /tmp directory, and the victim's token value from /usr/local/cwpsrv/logs/access_log, then use them to make a request to extract the victim's password (for the OS and phpMyAdmin) via an attacker account.
network
low complexity
control-webpanel CWE-532
6.5