Vulnerabilities > Information Exposure Through Log Files

DATE CVE VULNERABILITY TITLE RISK
2018-03-02 CVE-2018-7433 Information Exposure Through Log Files vulnerability in Ithemes Security
The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page.
network
low complexity
ithemes CWE-532
7.5
2018-03-02 CVE-2017-9278 Information Exposure Through Log Files vulnerability in Netiq Identity Manager
The NetIQ Identity Manager Oracle EBS driver before 4.0.2.0 sent EBS logs containing the driver authentication password, potentially disclosing this to attackers able to read the EBS tables.
network
low complexity
netiq CWE-532
critical
9.8
2018-03-02 CVE-2017-7434 Information Exposure Through Log Files vulnerability in Netiq Identity Manager 4.5
In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations could result in passwords being logged into exception logfiles.
network
low complexity
netiq CWE-532
critical
9.8
2018-03-01 CVE-2017-9271 Information Exposure Through Log Files vulnerability in multiple products
The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used.
local
low complexity
opensuse fedoraproject CWE-532
3.3
2018-02-16 CVE-2018-3609 Information Exposure Through Log Files vulnerability in Trendmicro Interscan Messaging Security Virtual Appliance 9.0/9.1
A vulnerability in the Trend Micro InterScan Messaging Security Virtual Appliance 9.0 and 9.1 management portal could allow an unauthenticated user to access sensitive information in a particular log file that could be used to bypass authentication on vulnerable installations.
network
high complexity
trendmicro CWE-532
8.1
2018-02-14 CVE-2018-2372 Information Exposure Through Log Files vulnerability in SAP Hana Extended Application Services 1.0
A plain keystore password is written to a system log file in SAP HANA Extended Application Services, 1.0, which could endanger confidentiality of SSL communication.
network
low complexity
sap CWE-532
6.5
2018-02-09 CVE-2018-1000060 Information Exposure Through Log Files vulnerability in Sensu Core
Sensu, Inc.
network
low complexity
sensu CWE-532
critical
9.8
2018-01-24 CVE-2018-1000018 Information Exposure Through Log Files vulnerability in Ovirt Ovirt-Hosted-Engine-Setup
An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals the root user's password in the log file.
local
low complexity
ovirt CWE-532
7.8
2018-01-14 CVE-2018-5693 Information Exposure Through Log Files vulnerability in Linuxmagic Magicspam 2.0.34
The LinuxMagic MagicSpam extension before 2.0.14-1 for Plesk allows local users to discover mailbox names by reading /var/log/magicspam/mslog.
local
low complexity
linuxmagic CWE-532
3.3
2018-01-04 CVE-2017-1727 Information Exposure Through Log Files vulnerability in IBM Security KEY Lifecycle Manager
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 discloses sensitive information in error messages that could aid an attacker in further attacks against the system.
network
low complexity
ibm CWE-532
4.3