Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Hana Extended Application Services HIGH 7.5
CVE-2019-0266

Under certain conditions SAP HANA Extended Application Services, version 1.0, advanced model (XS advanced) writes credentials of platform users to a …

Mitigation only
Fix from $1,950 2019-02-15
Api Connect CRITICAL 9.8
CVE-2019-4008

API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak. Authorization tokens in some URLs can result in the tokens being written to …

Fix: after 2018.4.1.1
Fix from $2,300 2019-02-07
Bigfix Compliance MEDIUM 5.3
CVE-2017-1198

IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) stores sensitive information in URL parameters. This may lead to information disclosure…

Fix: after 1.9.91
Fix from $1,600 2019-02-05
Kappa Firmware MEDIUM 6.5
CVE-2018-19014

Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Log files …

Mitigation only
Fix from $1,600 2019-01-28
Ceph HIGH 7.5
CVE-2018-16889

Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files …

Fix: after 13.2.4
Fix from $1,950 2019-01-28
Advanced Threat Prevention MEDIUM 5.5
CVE-2019-0021

On Juniper ATP, secret passphrase CLI inputs, such as "set mcm", are logged to /var/log/syslog in clear text, allowing authenticated local user to be…

Fix: 5.0.4+
Fix from $1,600 2019-01-15
Advanced Threat Prevention HIGH 7.8
CVE-2019-0029

Juniper ATP Series Splunk credentials are logged in a file readable by authenticated local users. Using these credentials an attacker can access the …

Fix: 5.0.3+
Fix from $1,950 2019-01-15
Advanced Threat Prevention MEDIUM 5.5
CVE-2019-0004

On Juniper ATP, the API key and the device key are logged in a file readable by authenticated local users. These keys are used for performing critica…

Fix: 5.0.3+
Fix from $1,600 2019-01-15
Debian Linux HIGH 7.8
CVE-2019-3500

aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and password in a file, which might allow local users to …

Patch available
Fix from $1,950 2019-01-02
V7 Firmware MEDIUM 5.5
CVE-2018-15001

The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform app with a pa…

No fix yet
Fix from $1,600 2018-12-28
Canvas Firmware MEDIUM 5.9
CVE-2018-15004

The Coolpad Canvas device with a build fingerprint of Coolpad/cp3636a/cp3636a:7.0/NRD90M/093031423:user/release-keys contains a platform app with a p…

No fix yet
Fix from $1,600 2018-12-28
1password MEDIUM 5.5
CVE-2018-19863

An issue was discovered in 1Password 7.2.3.BETA before 7.2.3.BETA-3 on macOS. A mistake in error logging resulted in instances where sensitive data p…

Mitigation only
Fix from $1,600 2018-12-22
Cloud Foundry Nfs Volume HIGH 8.8
CVE-2018-15797

Cloud Foundry NFS volume release, 1.2.x prior to 1.2.5, 1.5.x prior to 1.5.4, 1.7.x prior to 1.7.3, logs the cf admin username and password when runn…

Fix: 1.2.5 / 1.5.4+
Fix from $1,950 2018-12-05
Qt HIGH 7.5
CVE-2018-19865

A keystroke logging issue was discovered in Virtual Keyboard in Qt 5.7.x, 5.8.x, 5.9.x, 5.10.x, and 5.11.x before 5.11.3.

Fix: 5.11.3+
Fix from $1,950 2018-12-05
Vault HIGH 8.1
CVE-2018-19786

HashiCorp Vault before 1.0.0 writes the master key to the server log in certain unusual or misconfigured scenarios in which incorrect data comes from…

Fix: 1.0.0+
Fix from $1,950 2018-12-05
5n2 Firmware HIGH 7.5
CVE-2018-14700

Incorrect access control in the /mysql/api/logfile.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrie…

No fix yet
Fix from $1,950 2018-12-03
System Management Module Firmware MEDIUM 5.9
CVE-2018-16095

In System Management Module (SMM) versions prior to 1.06, the SMM records hashed passwords to a debug log when user authentication fails.

Fix: 1.06+
Fix from $1,600 2018-11-27
Circarlife Firmware CRITICAL 9.8
CVE-2018-17922

Circontrol CirCarLife all versions prior to 4.3.1, the PAP credentials of the device are stored in clear text in a log file that is accessible withou…

Fix: 4.3.1+
Fix from $2,300 2018-11-02
Robotic Process Automation With Automation Anywhere MEDIUM 5.5
CVE-2018-1876

IBM Robotic Process Automation with Automation Anywhere 11 could under certain cases, display the password in a Control Room log file after installat…

Patch available
Fix from $1,600 2018-11-02
Netscaler Sd Wan HIGH 7.5
CVE-2018-17447

An Information Exposure Through Log Files issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0…

Fix: 9.3.6 / 10.0.4+
Fix from $1,950 2018-10-23
Pivotal Container Service HIGH 8.8
CVE-2018-15763

Pivotal Container Service, versions prior to 1.2.0, contains an information disclosure vulnerability which exposes IaaS credentials to application lo…

Fix: 1.2+
Fix from $1,950 2018-10-05
Cloud Foundry Log Cache CRITICAL 9.8
CVE-2018-1264

Cloud Foundry Log Cache, versions prior to 1.1.1, logs its UAA client secret on startup as part of its envstruct report. A remote attacker who has ga…

Fix: 1.1.1+
Fix from $2,300 2018-10-05
Debian Linux MEDIUM 6.5
CVE-2018-0504

Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid

Fix: 1.31.1+
Fix from $1,600 2018-10-04
GitLab CRITICAL 9.8
CVE-2018-16049

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Sensitive …

Fix: 11.0.6 / 11.1.5+
Fix from $2,300 2018-10-03
Spectrum Protect Plus HIGH 7.8
CVE-2018-1768

IBM Spectrum Protect Plus 10.1.0 and 10.1.1 could disclose sensitive information when an authorized user executes a test operation, the user id an pa…

Patch available
Fix from $1,950 2018-09-26
Azure Repository HIGH 8.1
CVE-2018-3827

A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly elasticsearch-cloud-azure) plugin. When the repository-azu…

Fix: after 6.2.4
Fix from $1,950 2018-09-19
Elastic Cloud Enterprise HIGH 7.5
CVE-2018-3828

Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exception condit…

Fix: 1.1.4+
Fix from $1,950 2018-09-19
Cloud Foundry Container Runtime HIGH 8.8
CVE-2018-1223

Cloud Foundry Container Runtime (kubo-release), versions prior to 0.14.0, may leak UAA and vCenter credentials to application logs. A malicious user …

Fix: 0.14.0+
Fix from $1,950 2018-09-17
Pivotal Cloud Cache HIGH 8.8
CVE-2018-1198

Pivotal Cloud Cache, versions prior to 1.3.1, prints a superuser password in plain text during BOSH deployment logs. A malicious user with access to …

Fix: 1.3.1+
Fix from $1,950 2018-09-17
Wonder Rc555l Firmware MEDIUM 5.5
CVE-2018-6599

An issue was discovered on Orbic Wonder Orbic/RC555L/RC555L:7.1.2/N2G47H/329100b:user/release-keys devices, allowing attackers to obtain sensitive in…

Mitigation only
Fix from $1,600 2018-08-29