The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due t
Plaintext Password vulnerability in AddAdmin.py in cms-dev/cms v1.4.rc1, allows attackers to gain sensitive information
Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Administrator on Linux allows local
All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, a
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v2.6.0-r
Dell PowerScale OneFS 9.5.0.x, contains an insertion of sensitive information into log file vulnerability in SNMPv3. A
A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, th
IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to an Information Disclosure as sensitive informa
IBM Maximo Application Suite 8.8.0 and 8.9.0 stores potentially sensitive information that could be read by a local user
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 stores potentially sens
Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 compon
An issue in Archer Platform before v.6.13 fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to obtain se
Dell ECS Streamer, versions prior to 2.0.7.1, contain an insertion of sensitive information in log files vulnerability.
The logs of sensitive information (PII) or hardware identifier should only be printed in Android "userdebug" or "eng" bu
An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting fro
In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is v
A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets we
Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 ins
An issue was discovered in Acuant AsureID Sentinel before 5.2.149. It uses the root of the C: drive for the i-Dentify an
aws-sigv4 is a rust library for low level request signing in the aws cloud platform. The `aws_sigv4::SigningParams` stru
When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that passw
Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are report
Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to f
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in watchOS 9.5,
Dell Wyse ThinOS versions prior to 2303 (9.4.1141) contain a sensitive information disclosure vulnerability. An unauthe
Dell Wyse ThinOS versions prior to 2306 (9.4.2103) contain a sensitive information disclosure vulnerability. A maliciou
Dell Wyse ThinOS versions prior to 2208 (9.3.2102) contain a sensitive information disclosure vulnerability. An unauthe
Sensitive information leak through log files. The following products are affected: Acronis Agent (Linux, macOS, Windows)
Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect Cloud Agent (Li
Sensitive data could be exposed in logs of subiquity version 23.09.1 and earlier. An attacker in the adm group could use
When on BIG-IP DNS or BIG-IP LTM enabled with DNS Services License, and a TSIG key is created, it is logged in plaintex
When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audi
An insertion of sensitive information into log file vulnerability in Fortinet FortiGuest 1.0.0 allows a local attacker t
ydb-go-sdk is a pure Go native and database/sql driver for the YDB platform. Since ydb-go-sdk v3.48.6 if you use a custo
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.1 and
Insertion of sensitive information into log file in some Intel(R) On Demand software before versions 1.16.2, 2.1.1, 3.1.
Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attack
Jenkins Pipeline Maven Integration Plugin 1330.v18e473854496 and earlier does not properly mask (i.e., replace with aste
CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. In affected versions successful lo
The Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain sensitive information from appl
A vulnerability in the logging component of Cisco Duo Authentication Proxy could allow an authenticated, remote attacker
An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 16.0.8, all versions starting
Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in loggin
If Elastic Endpoint (v7.9.0 - v8.10.3) is configured to use a non-default option in which the logging level is explicitl
Mattermost fails to sanitize post metadata during audit logging resulting in permalinks contents being logged
The affected versions of MongoDB Atlas Kubernetes Operator may print sensitive information like GCP service account keys
Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 allows attackers to ac
Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause
Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass
Audit logs on F5OS-A may contain undisclosed sensitive information. Note: Software versions which have reached End of
Frequently Asked Questions
What is CWE-532?
CWE-532 (CWE-532) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-532?
There are 1,485 CVE records associated with CWE-532 in our database. Of these, 54 are critical severity, 255 are high severity, and 707 are medium severity.
How can I protect against CWE-532 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-532 using AI-powered security agents.
Detect CWE-532 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-532 vulnerabilities across your infrastructure.
Get Started