Threats Tagged 'cwe-532'
View all threats tagged with 'cwe-532'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-532'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-0637: CWE-532: Insertion of Sensitive Information into Log Files in WSO2 WSO2 API ManagerCVE-2026-0637 0 When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values. A malicious actor with access to the 'wso2carbon' log files could retrieve sensitive information, such as user credentials or other confidential data, that was inadvertently logged due to misconfiguration, potentially leading to unauthorized access. Join the discussion | CVE Database V5 | 08/06/2026, 07:33:20 UTC Added: 08/06/2026, 08:11:48 UTC |
CVE-2026-21766: CWE-522 Insufficiently Protected Credentials in HCLSoftware HCL Digital Experience and Digital Experience ComposeCVE-2026-21766 0 The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. Under certain very specific use cases and specific configurations, sensitive information may be written to web server logs. This only affects applications using the default login portlet. Join the discussion | CVE Database V5 | 08/05/2026, 20:11:19 UTC Added: 08/05/2026, 20:26:48 UTC |
CVE-2026-65311: CWE-306 Missing authentication for critical function in ANDRITZ HIPASE-250CVE-2026-65311 0 ANDRITZ HIPASE-250 contains an unauthenticated HTTP endpoint that allows remote attackers to change the server's logging level and target. This vulnerability can be exploited to suppress audit logging, potentially hiding malicious activity. No authentication is required to access this critical function. The vulnerability has a medium severity score of 5.3 and does not impact confidentiality or availability but affects integrity by allowing log tampering. No patch or official remediation information is currently available. Join the discussion | CVE Database V5 | 07/31/2026, 07:30:07 UTC Added: 07/31/2026, 08:22:52 UTC |
CVE-2026-12947: CWE-532 Insertion of Sensitive Information into Log File in IBM App Connect EnterpriseCVE-2026-12947 0 CVE-2026-12947 is a vulnerability in IBM App Connect Enterprise versions 13.0.1.0 through 13.0.7.2 and 12.0.1.0 through 12.0.12.27 where sensitive information may be stored in log files accessible to local users. This could lead to unauthorized disclosure of sensitive data. The vulnerability has a high severity with a CVSS score of 7.5. No official patch or remediation guidance is currently provided by the vendor. Join the discussion | CVE Database V5 | 07/30/2026, 14:17:30 UTC Added: 07/30/2026, 16:52:57 UTC |
CVE-2026-44105: CWE-532 Insertion of Sensitive Information into Log File in Phoenix Contact CHARX SEC-3150CVE-2026-44105 0 CVE-2026-44105 is a vulnerability in Phoenix Contact CHARX SEC-3150 version 1.0.0 where credentials for the local user "user-app" are written to log files. This exposure could allow a low-privileged local attacker with access to these logs to authenticate via SSH as the limited user "user-app", potentially disrupting charging operations. Join the discussion | CVE Database V5 | 07/30/2026, 06:53:13 UTC Added: 07/30/2026, 07:22:40 UTC |
CVE-2026-59326: CWE-532 Insertion of Sensitive Information into Log File in Spring Spring Tools for EclipseCVE-2026-59326 0 CVE-2026-59326 is a low-severity vulnerability in Spring Tools for Eclipse (version 5.2.0 and earlier) where the Spring Boot language server logs the raw value of proxy environment variables, including embedded Basic-auth credentials, at INFO level without redaction. This can lead to unintended disclosure of proxy credentials through log files, which may be accessible to other local users or attached to bug reports. Join the discussion | CVE Database V5 | 07/30/2026, 05:34:08 UTC Added: 07/30/2026, 06:24:12 UTC |
CVE-2026-1918: CWE-532 Insertion of Sensitive Information into Log File in IBM Sterling B2B IntegratorCVE-2026-1918 0 IBM Sterling B2B Integrator and IBM Sterling File Gateway versions 6.2.0.0 through 6.2.2.0_1 store potentially sensitive information in log files. This information could be accessed by users with privileged access to the system. The vulnerability is classified as CWE-532, indicating insertion of sensitive information into log files. The CVSS 3.1 base score is 4.9, reflecting a medium severity level with high confidentiality impact but no impact on integrity or availability. Join the discussion | GCVE Database | 07/28/2026, 19:45:06 UTC Added: 07/28/2026, 23:50:07 UTC |
CVE-2026-14528: CWE-532 Insertion of Sensitive Information into Log File in IBM WebSphere Application ServerCVE-2026-14528 0 IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information. Join the discussion | GCVE Database | 07/28/2026, 20:37:32 UTC Added: 07/28/2026, 23:50:07 UTC |
CVE-2026-14528: CWE-532 Insertion of Sensitive Information into Log File in IBM WebSphere Application ServerCVE-2026-14528 0 CVE-2026-14528 is a high-severity vulnerability in IBM WebSphere Application Server versions 8.5 and 9.0. It involves the insertion of sensitive information into log files, which could allow a remote attacker to obtain this sensitive data. The vulnerability is classified under CWE-532. No official patch or remediation guidance has been provided yet by IBM. Join the discussion | CVE Database V5 | 07/28/2026, 20:37:32 UTC Added: 07/28/2026, 21:07:52 UTC |
CVE-2026-1918: CWE-532 Insertion of Sensitive Information into Log File in IBM Sterling B2B IntegratorCVE-2026-1918 0 IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 stores potentially sensitive information in log files that could be read by a privileged user. Join the discussion | CVE Database V5 | 07/28/2026, 19:45:06 UTC Added: 07/28/2026, 20:07:40 UTC |
Showing 1 to 10 of 16 results