Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Octopus Deploy MEDIUM 6.5
CVE-2019-14268

In Octopus Deploy versions 3.0.19 to 2019.7.2, when a web request proxy is configured, an authenticated user (in certain limited circumstances) could…

Fix: after 2019.7.2
Fix from $1,600 2019-07-25
Wallet MEDIUM 6.5
CVE-2019-13098

The user password via the registration form of TronLink Wallet 2.2.0 is stored in the log when the class CreateWalletTwoActivity is called. Other aut…

No fix yet
Fix from $1,600 2019-07-22
Docker HIGH 7.5
CVE-2019-13509

In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometim…

Fix: 18.09.8+
Fix from $1,950 2019-07-18
Virtualization Manager MEDIUM 5.5
CVE-2019-10194

Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could b…

Mitigation only
Fix from $1,600 2019-07-11
GitLab MEDIUM 6.5
CVE-2018-19583

GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, would log access tokens in the Workhorse logs, perm…

Fix: 11.3.11 / 11.4.8+
Fix from $1,600 2019-07-10
Robotic Process Automation With Automation Anywhere MEDIUM 5.5
CVE-2019-4299

IBM Robotic Process Automation with Automation Anywhere 11 could allow a local user to obtain highly sensitive information from log files when debugg…

Fix: 11.0.0.5+
Fix from $1,600 2019-07-01
Data Center Network Manager MEDIUM 5.3
CVE-2019-1622EPSS 79%

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to …

No fix yet
Fix from $1,600 2019-06-27
Bosh HIGH 7.8
CVE-2019-11271

Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials when configured to use a MySQL…

Fix: 270.1.1+
Fix from $1,950 2019-06-19
Undertow CRITICAL 9.8
CVE-2019-3888

A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connector…

Fix: 2.0.21+
Fix from $2,300 2019-06-12
Cfengine HIGH 8.8
CVE-2019-9929

Northern.tech CFEngine Enterprise 3.12.1 has Insecure Permissions.

No fix yet
Fix from $1,950 2019-06-06
Photo Sharing Plus HIGH 8.1
CVE-2019-11336

Sony Bravia Smart TV devices allow remote attackers to retrieve the static Wi-Fi password (used when the TV is acting as an access point) by using th…

No fix yet
Fix from $1,950 2019-05-14
Xclarity Administrator MEDIUM 5.9
CVE-2019-6158

An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered HTTP proxy credentials being written to a log file in clear tex…

Fix: 2.4.0+
Fix from $1,600 2019-05-03
Projectsend HIGH 7.5
CVE-2019-11492

ProjectSend before r1070 writes user passwords to the server logs.

Fix: 1070+
Fix from $1,950 2019-04-26
Aquarius Cms HIGH 7.5
CVE-2019-9734

Aquarius CMS through 4.3.5 writes POST and GET parameters (including passwords) to a log file due to an overwriting of configuration parameters under…

Fix: after 4.3.5
Fix from $1,950 2019-04-24
Aquarius Cms HIGH 7.5
CVE-2019-9724

aquaverde Aquarius CMS through 4.3.5 allows Information Exposure through Log Files because of an error in the Log-File writer component.

Fix: after 4.3.5
Fix from $1,950 2019-04-24
Flex System X240 M4 Firmware HIGH 7.5
CVE-2019-6157

In various firmware versions of Lenovo System x, the integrated management module II (IMM2)'s first failure data capture (FFDC) includes the web serv…

Fix: 5.30+
Fix from $1,950 2019-04-22
Satellite HIGH 7.8
CVE-2019-3891

It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin da…

No fix yet
Fix from $1,950 2019-04-15
H660rm Firmware HIGH 8.8
CVE-2019-9976

The Boa server configuration on DASAN H660RM devices with firmware 1.03-0022 logs POST data to the /tmp/boa-temp file, which allows logged-in users t…

Mitigation only
Fix from $1,950 2019-04-11
Service Insight HIGH 7.8
CVE-2019-0032

A password management issue exists where the Organization authentication username and password were stored in plaintext in log files. A locally authe…

Fix: 18.1r1+
Fix from $1,950 2019-04-10
Cloud Private MEDIUM 5.5
CVE-2019-4143

The IBM Cloud Private Key Management Service (IBM Cloud Private 3.1.1 and 3.1.2) could allow a local user to obtain sensitive from the KMS plugin con…

Mitigation only
Fix from $1,600 2019-04-08
Openstack HIGH 7.5
CVE-2018-16856

In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.…

Fix: 2.0.2-5 / 3.0.1-0.20181009115732+
Fix from $1,950 2019-03-26
Openstack HIGH 7.8
CVE-2019-3830

A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints sensitive configuration data t…

Fix: after 2015.1.4
Fix from $1,950 2019-03-26
Logstash CRITICAL 9.8
CVE-2019-7612

A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified …

Fix: 5.6.15 / 6.6.1+
Fix from $2,300 2019-03-25
Webgalamb HIGH 7.5
CVE-2018-19513

In Webgalamb through 7.0, log files are exposed to the internet with predictable files/logs/sql_error_log/YYYY-MM-DD-sql_error_log.log filenames. The…

Fix: after 7.0
Fix from $1,950 2019-03-21
Securaccess HIGH 7.0
CVE-2018-18466

An issue was discovered in SecurEnvoy SecurAccess 9.3.502. When put in Debug mode and used for RDP connections, the application stores the emergency …

Mitigation only
Fix from $1,950 2019-03-21
Passport MEDIUM 5.5
CVE-2018-17499

Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of unenc…

Mitigation only
Fix from $1,600 2019-03-21
Archer Grc Platform MEDIUM 5.5
CVE-2019-3715

RSA Archer versions, prior to 6.5 SP1, contain an information exposure vulnerability. Users' session information is logged in plain text in the RSA A…

Fix: 6.5+
Fix from $1,600 2019-03-13
Archer Grc Platform HIGH 7.8
CVE-2019-3716

RSA Archer versions, prior to 6.5 SP2, contain an information exposure vulnerability. The database connection password may get logged in plain text i…

Fix: 6.5.2.0+
Fix from $1,950 2019-03-13
Java Software Development Kit HIGH 7.5
CVE-2019-0741EPSS 7%

An information disclosure vulnerability exists in the way Azure IoT Java SDK logs sensitive information, aka 'Azure IoT Java SDK Information Disclosu…

Patch available
Fix from $1,950 2019-03-05
Octopus Deploy MEDIUM 6.5
CVE-2019-8944

An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 (and before 2018.10.4 LTS) allows remote authenticat…

Fix: 2019.1.8+
Fix from $1,600 2019-02-20