Sensitive Information Exposure in F5 BIG-IP by Unauthorized Access
CVE-2016-6249
5.3MEDIUM
What is CVE-2016-6249?
The F5 BIG-IP product line experiences a vulnerability wherein REST requests that timeout during user authentication may inadvertently log sensitive information, such as passwords, in plaintext form. This information is stored in the /var/log/restjavad.0.log file, creating an opportunity for local users to exploit this logging behavior to gain unauthorized access to sensitive data.
Affected Version(s)
F5 BIG-IP, REST Framework Logging BIG-IP 12.0.0, BIG-IP 11.5.0 - 11.6.1