CWE-532Base2 in KEV

Insertion of Sensitive Information into Log File

Incomplete in the CWE catalog · 730 CVEs mapped

730
CVEs mapped
2
In KEV
5.5
Median CVSS
What it is

The product writes sensitive information to a log file.

Recent examples
5.1cvss
CVE-2026-17442

CVE-2026-17442 - MEDIUM Severity Vulnerability

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to credentials being written to trace logs in cleartext.

MEDIUMno explanation yet
0%
epss
6.2cvss
CVE-2026-16689

CVE-2026-16689 - MEDIUM Severity Vulnerability

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of credentials.

MEDIUMno explanation yet
0%
epss
6.2cvss
CVE-2026-19649

CVE-2026-19649 - MEDIUM Severity Vulnerability

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of database credentials.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-532
Abstraction
Base
Structure
Simple
Status
Incomplete