Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-532'

View all threats tagged with 'cwe-532'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-532

Threats Tagged 'cwe-532'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-17442: CWE-532 Insertion of Sensitive Information into Log File in IBM App Connect EnterpriseCVE-2026-17442
0

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to credentials being written to trace logs in cleartext.

Join the discussion
CVE-2026-16689: CWE-532 Insertion of Sensitive Information into Log File in IBM App Connect EnterpriseCVE-2026-16689
0

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of credentials.

Join the discussion
CVE-2026-19649: CWE-532 Insertion of Sensitive Information into Log File in IBM App Connect EnterpriseCVE-2026-19649
0

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of database credentials.

Join the discussion
CVE-2026-55221: CWE-532: Insertion of Sensitive Information into Log File in malach-it boruta-serverCVE-2026-55221
0

Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.10.0, Boruta logged sensitive OAuth and OpenID Connect values in business event logs. Logged values could include access tokens, refresh tokens, authorization codes, agent tokens, direct-post codes, ID tokens, VP tokens, and tokens submitted to introspection or revocation endpoints. An attacker with access to Boruta logs, log aggregation systems, or the administration log viewer could recover these credentials and use them until expiration or revocation. This issue has been patched in version 0.10.0.

Join the discussion
CVE-2026-78174: CWE-200 in WatchGuard DimensionCVE-2026-78174
0

WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that administrator is logged in, enabling account takeover.

Join the discussion
CVE-2026-81530: CWE-532: Insertion of Sensitive Information into Log File in MongoDB C# DriverCVE-2026-81530
0

A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes sensitive key-management credential material supplied by the application to be reproduced verbatim in the driver's human-readable diagnostic representation of its client settings, instead of being masked as other secret fields are. A party able to read the application's logs, diagnostic output, or a process memory dump may thereby recover the plaintext credentials and use them to decrypt protected field data.

Join the discussion
CVE-2026-59302: CWE-532 Insertion of Sensitive Information into Log File in Spring Spring Cloud StreamCVE-2026-59302
0

Potential for logging sensitive data in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6

Join the discussion
CVE-2026-59301: CWE-532 Insertion of Sensitive Information into Log File in Spring Spring Cloud FunctionCVE-2026-59301
0

Potential for logging sensitive data in Spring Cloud Function Azure. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7

Join the discussion
CVE-2026-59300: CWE-532 Insertion of Sensitive Information into Log File in Spring Spring Cloud FunctionCVE-2026-59300
0

Potential for logging sensitive data in Spring Cloud Function AWS. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 Spring Cloud Function 3.2.16 and earlier

Join the discussion
CVE-2026-75573: CWE-532: Insertion of Sensitive Information into Log File in MongoDB BI ConnectorCVE-2026-75573
0

In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A local user with access to the captured command output and encrypted key file may use the disclosed password to access the associated TLS client key.

Join the discussion

Showing 1 to 10 of 27 results

Filters:Tag: cwe-532
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses