Threats Tagged 'cwe-532'
View all threats tagged with 'cwe-532'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-532'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-17442: CWE-532 Insertion of Sensitive Information into Log File in IBM App Connect EnterpriseCVE-2026-17442 0 IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to credentials being written to trace logs in cleartext. Join the discussion | CVE Database V5 | 09/04/2026, 16:36:02 UTC Added: 09/04/2026, 16:52:49 UTC |
CVE-2026-16689: CWE-532 Insertion of Sensitive Information into Log File in IBM App Connect EnterpriseCVE-2026-16689 0 IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of credentials. Join the discussion | CVE Database V5 | 09/04/2026, 16:42:13 UTC Added: 09/04/2026, 16:52:46 UTC |
CVE-2026-19649: CWE-532 Insertion of Sensitive Information into Log File in IBM App Connect EnterpriseCVE-2026-19649 0 IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of database credentials. Join the discussion | CVE Database V5 | 09/04/2026, 15:18:16 UTC Added: 09/04/2026, 15:37:55 UTC |
CVE-2026-55221: CWE-532: Insertion of Sensitive Information into Log File in malach-it boruta-serverCVE-2026-55221 0 Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.10.0, Boruta logged sensitive OAuth and OpenID Connect values in business event logs. Logged values could include access tokens, refresh tokens, authorization codes, agent tokens, direct-post codes, ID tokens, VP tokens, and tokens submitted to introspection or revocation endpoints. An attacker with access to Boruta logs, log aggregation systems, or the administration log viewer could recover these credentials and use them until expiration or revocation. This issue has been patched in version 0.10.0. Join the discussion | CVE Database V5 | 09/02/2026, 17:28:15 UTC Added: 09/02/2026, 17:43:02 UTC |
CVE-2026-78174: CWE-200 in WatchGuard DimensionCVE-2026-78174 0 WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that administrator is logged in, enabling account takeover. Join the discussion | CVE Database V5 | 08/27/2026, 23:26:30 UTC Added: 08/28/2026, 02:08:11 UTC |
CVE-2026-81530: CWE-532: Insertion of Sensitive Information into Log File in MongoDB C# DriverCVE-2026-81530 0 A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes sensitive key-management credential material supplied by the application to be reproduced verbatim in the driver's human-readable diagnostic representation of its client settings, instead of being masked as other secret fields are. A party able to read the application's logs, diagnostic output, or a process memory dump may thereby recover the plaintext credentials and use them to decrypt protected field data. Join the discussion | CVE Database V5 | 08/27/2026, 18:32:32 UTC Added: 08/27/2026, 20:24:33 UTC |
CVE-2026-59302: CWE-532 Insertion of Sensitive Information into Log File in Spring Spring Cloud StreamCVE-2026-59302 0 Potential for logging sensitive data in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6 Join the discussion | CVE Database V5 | 08/27/2026, 17:57:58 UTC Added: 08/27/2026, 20:24:24 UTC |
CVE-2026-59301: CWE-532 Insertion of Sensitive Information into Log File in Spring Spring Cloud FunctionCVE-2026-59301 0 Potential for logging sensitive data in Spring Cloud Function Azure. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 Join the discussion | CVE Database V5 | 08/27/2026, 17:57:57 UTC Added: 08/27/2026, 20:24:24 UTC |
CVE-2026-59300: CWE-532 Insertion of Sensitive Information into Log File in Spring Spring Cloud FunctionCVE-2026-59300 0 Potential for logging sensitive data in Spring Cloud Function AWS. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 Spring Cloud Function 3.2.16 and earlier Join the discussion | CVE Database V5 | 08/27/2026, 17:57:57 UTC Added: 08/27/2026, 20:24:24 UTC |
CVE-2026-75573: CWE-532: Insertion of Sensitive Information into Log File in MongoDB BI ConnectorCVE-2026-75573 0 In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A local user with access to the captured command output and encrypted key file may use the disclosed password to access the associated TLS client key. Join the discussion | CVE Database V5 | 08/27/2026, 16:01:55 UTC Added: 08/27/2026, 16:54:05 UTC |
Showing 1 to 10 of 27 results