CVE Vulnerabilities

CVE-2017-9615

Insertion of Sensitive Information into Log File

Published: Jun 26, 2017 | Modified: Apr 20, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Password exposure in Cognito Software Moneyworks 8.0.3 and earlier allows attackers to gain administrator access to all data, because verbose logging writes the administrator password to a world-readable file.

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
MoneyworksCognito*8.0.3 (including)

Potential Mitigations

References