Under certain conditions, Teradici PCoIP Agents for Windows prior to version 20.10.0 and Teradici PCoIP Agents for Linux
A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged
A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by th
A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protect
Improper log management vulnerability in Galaxy Watch PlugIn prior to version 2.2.05.21033151 allows attacker with log p
Improper log management vulnerability in Galaxy Watch3 PlugIn prior to version 2.2.09.21033151 allows attacker with log
Improper log management vulnerability in Watch Active PlugIn prior to version 2.2.07.21033151 allows attacker with log p
Improper log management vulnerability in Watch Active2 PlugIn prior to 2.2.08.21033151 version allows attacker with log
iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A locally authenticated attacker can read the sy
Nextcloud server is an open source, self hosted personal cloud. In affected versions logging of exceptions may have resu
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12). The affected application wr
A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC
There is an information leakage vulnerability in FusionCompute 6.5.1, eCNS280_TD V100R005C00 and V100R005C10. Due to the
In handleUpdateNetworkState of GnssNetworkConnectivityHandler.java , there is a possible APN disclosure due to log infor
The `com.bmuschko:gradle-vagrant-plugin` Gradle plugin contains an information disclosure vulnerability due to the loggi
BMC Remedy Mid Tier 9.1SP3 is affected by log hijacking. Remote logging can be accessed by unauthenticated users, allowi
TYPO3 is an open source PHP based web content management system. In versions 9.0.0 through 9.5.27, 10.0.0 through 10.4.1
An information exposure through log file vulnerability exists in Cortex XSOAR software where the secrets configured for
Elasticsearch versions before 7.10.0 and 6.8.14 have an information disclosure issue when audit logging and the emit_req
A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive p
On all versions of Guided Configuration before 8.0.0, when a configuration that contains secure properties is created an
An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where configuration
A ZTE Smart STB is impacted by an information leak vulnerability. The device did not fully verify the log, so attackers
An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or
There is an information leakage vulnerability in some huawei products. Due to the properly storage of specific informati
An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where secrets in PAN
A flaw was found in the AMQ Broker that discloses JDBC encrypted usernames and passwords when provided in the AMQ Broker
All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all
In sspRequestCallback of BondStateMachine.java, there is a possible leak of Bluetooth MAC addresses due to log informati
Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versi
Insertion of information into log file in firmware for some Intel(R) SSD DC may allow a privileged user to potentially e
A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged
A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unified Communications Man
A clear text storage of sensitive information into log file vulnerability in FortiADCManager 5.3.0 and below, 5.2.1 and
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly logged sensitive suppr
NetApp Cloud Manager versions prior to 3.9.9 log sensitive information that is available only to authenticated users. Cu
NetApp Cloud Manager versions prior to 3.9.9 log sensitive information when an Active Directory connection fails. The lo
PuppetDB logging included potentially sensitive system information.
Dell Wyse ThinOS, versions 9.0, 9.1, and 9.1 MR1, contain a Sensitive Information Disclosure Vulnerability. An authentic
An information exposure through log file vulnerability exists in the Palo Alto Networks Prisma Cloud Compute Console whe
Automox Agent prior to version 31 logs potentially sensitive information in local log files, which could be used by a lo
The Elastic APM agent for Go versions before 1.11.0 can leak sensitive HTTP header information when logging the details
In OnMetadataChangedListener of AdvancedBluetoothDetailsHeaderController.java, there is a possible leak of Bluetooth MAC
An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where the connection
IBM App Connect Enterprise Certified Container 1.0, 1.1, 1.2, and 1.3 could allow a privileged user to obtain sensitive
Information Exposure vulnerability in Samsung Account prior to version 12.1.1.3 allows physically proximate attackers to
Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in o
A vulnerability in the audit logging component of Cisco Digital Network Architecture (DNA) Center could allow an authent
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered Windows OS credentials, used to pe
Under certain conditions the SAP Adaptive Server Enterprise, version 16.0, allows an attacker to access encrypted sensit
Frequently Asked Questions
What is CWE-532?
CWE-532 (CWE-532) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-532?
There are 1,485 CVE records associated with CWE-532 in our database. Of these, 54 are critical severity, 255 are high severity, and 707 are medium severity.
How can I protect against CWE-532 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-532 using AI-powered security agents.
Detect CWE-532 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-532 vulnerabilities across your infrastructure.
Get Started