Logging Vulnerability in BIG-IP APM Edge Client Affects F5 Networks
CVE-2019-6656
7.5HIGH
Summary
The F5 Networks BIG-IP APM Edge Client versions prior to 7.1.8 expose sensitive information by logging full application session IDs in log files. This practice can lead to potential unauthorized access as the session IDs may reveal user session data. It is crucial for users of affected BIG-IP APM versions, including 15.0.0-15.0.1, 14.1.0-14.1.0.6, and others, to upgrade to the fixed version. Starting with BIG-IP APM version 13.1.0, the APM Client components can be updated independently from the BIG-IP software, enabling better security management.
Affected Version(s)
BIG-IP APM Edge Client 15.0.0-15.0.1, 14,1.0-14.1.0.6, 14.0.0-14.0.0.4, 13.0.0-13.1.1.5, 12.1.0-12.1.5, 11.5.1-11.6.5
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved