IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation
An issue has been identified in MongoDB Server where unredacted queries may inadvertently appear in server logs when cer
Brocade SANnav before Brocade SANnav 2.4.0a could log database passwords in clear text in audit logs when the daily data
A insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11.5.1, 11.4.6, 11.4.5 al
Information exposure through log file vulnerability in LDAP import feature in Liferay Portal 7.4.0 through 7.4.3.97, and
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7,
Using API in the 2N OS device, authorized user can enable logging, which discloses valid authentication tokens in system
In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log
In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs
Dell PowerFlex Manager VM, versions prior to 4.6.2.1, contains an Insertion of Sensitive Information into Log File vulne
A vulnerability has been identified in Rancher Manager, where sensitive information, including secret data, cluster imp
An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiADC 7.4.0, FortiADC 7.2 all
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to
An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior
The SAP NetWeaver Application Server ABAP and ABAP Platform Internet Communication Manager (ICM) permits authorized user
Medtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext
BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated atta
On affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.3 and
IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 thro
Snowflake, a platform for using artificial intelligence in the context of cloud computing, has a vulnerability in the Sn
In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea.log file
In Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, a
libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, are vulnerable to
Insertion of sensitive information into log file for some Intel(R) Local Manageability Service software before version 2
IBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local use
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia
Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on ser
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Starting in version 0.7.0 and prior to
ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging
TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has
Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs.
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. When debugging is enabled for Himmelbla
A insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4 al
In Splunk Add-on for Palo Alto Networks versions below 2.0.2, the add-on exposes client secrets in plain text in the _in
@backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. Prior to version 2.1.1
Insertion of sensitive information into log file issue exists in "region PAY" App for Android prior to 1.5.28. If exploi
A insertion of sensitive information into log file in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5,
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.5.5 and 18.6 before 18.6.3 tha
IBM Transformation Extender Advanced 10.0.1 stores potentially sensitive information in log files that could be read by
In some circumstances, debug artifacts uploaded by the CodeQL Action after a failed code scanning workflow run may conta
kube-audit-rest is a simple logger of mutation/creation requests to the k8s api. If the "full-elastic-stack" example vec
A vulnerability exists in Docker Desktop prior to version 4.39.0 that could lead to the unintentional disclosure of sens
Buildx is a Docker CLI plugin that extends build capabilities using BuildKit. Cache backends support credentials by set
Metabase is an open source Business Intelligence and Embedded Analytics tool. When admins change Snowflake connection de
Recording of environment variables, configured for running containers, in Docker Desktop application logs could lead to
zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. Prior to v
A flaw exists in FlashArray whereby the Key Encryption Key (KEK) is logged during key rotation when RDL is configured.
Frequently Asked Questions
What is CWE-532?
CWE-532 (CWE-532) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-532?
There are 1,485 CVE records associated with CWE-532 in our database. Of these, 54 are critical severity, 255 are high severity, and 707 are medium severity.
How can I protect against CWE-532 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-532 using AI-powered security agents.
Detect CWE-532 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-532 vulnerabilities across your infrastructure.
Get Started