|
Status: Incomplete Weakness ID: 533 (Weakness Variant)Description Summary A server.log file was found. This can give information on whatever application left the file. Usually this can give full path names and system information, and sometimes usernames and passwords. Affected Resources File/DirectoryPotential Mitigations Consider seriously the sensitivity of the information written into log files. Do not write secrets into the log files. Protect log files against unauthorized read/write. Relationships
Taxonomy Mappings
Time of Introduction Implementation OperationContent History Submissions Anonymous Tool Vendor (under NDA). (Externally Mined) Modifications Eric Dalci. Cigital. 2008-07-01. (External) updated Potential_Mitigations, Time_of_Introduction CWE Content Team. MITRE. 2008-09-08. (Internal) updated Relationships, Taxonomy_Mappings |
|
|
|||