Vulnerabilities > Information Exposure Through Log Files

DATE CVE VULNERABILITY TITLE RISK
2019-04-11 CVE-2019-9976 Information Exposure Through Log Files vulnerability in Dasannetworks H660Rm Firmware 1.030022
The Boa server configuration on DASAN H660RM devices with firmware 1.03-0022 logs POST data to the /tmp/boa-temp file, which allows logged-in users to read the credentials of administration web interface users.
network
low complexity
dasannetworks CWE-532
8.8
2019-04-08 CVE-2019-4143 Information Exposure Through Log Files vulnerability in IBM Cloud Private 3.1.1/3.1.2
The IBM Cloud Private Key Management Service (IBM Cloud Private 3.1.1 and 3.1.2) could allow a local user to obtain sensitive from the KMS plugin container log.
local
low complexity
ibm CWE-532
5.5
2019-03-26 CVE-2019-3830 Information Exposure Through Log Files vulnerability in multiple products
A vulnerability was found in ceilometer before version 12.0.0.0rc1.
local
low complexity
openstack redhat CWE-532
7.8
2019-03-26 CVE-2018-16856 Information Exposure Through Log Files vulnerability in multiple products
In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users.
network
low complexity
openstack redhat CWE-532
7.5
2019-03-25 CVE-2019-7612 Information Exposure Through Log Files vulnerability in multiple products
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs.
network
low complexity
elastic netapp CWE-532
critical
9.8
2019-03-21 CVE-2018-19513 Information Exposure Through Log Files vulnerability in ENS Webgalamb 6.0/7.0
In Webgalamb through 7.0, log files are exposed to the internet with predictable files/logs/sql_error_log/YYYY-MM-DD-sql_error_log.log filenames.
network
low complexity
ens CWE-532
7.5
2019-03-21 CVE-2018-18466 Information Exposure Through Log Files vulnerability in Securenvoy Securaccess 9.3.502
An issue was discovered in SecurEnvoy SecurAccess 9.3.502.
local
high complexity
securenvoy CWE-532
7.0
2019-03-13 CVE-2019-3716 Information Exposure Through Log Files vulnerability in RSA Archer GRC Platform
RSA Archer versions, prior to 6.5 SP2, contain an information exposure vulnerability.
local
low complexity
rsa CWE-532
7.8
2019-03-13 CVE-2019-3715 Information Exposure Through Log Files vulnerability in RSA Archer GRC Platform
RSA Archer versions, prior to 6.5 SP1, contain an information exposure vulnerability.
local
low complexity
rsa CWE-532
5.5
2019-03-05 CVE-2019-0741 Information Exposure Through Log Files vulnerability in Microsoft Java Software Development KIT
An information disclosure vulnerability exists in the way Azure IoT Java SDK logs sensitive information, aka 'Azure IoT Java SDK Information Disclosure Vulnerability'.
network
low complexity
microsoft CWE-532
7.5