CVE Vulnerabilities

CVE-2019-6656

Insertion of Sensitive Information into Log File

Published: Sep 25, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

BIG-IP APM Edge Client before version 7.1.8 (7180.2019.508.705) logs the full apm session ID in the log files. Vulnerable versions of the client are bundled with BIG-IP APM versions 15.0.0-15.0.1, 14,1.0-14.1.0.6, 14.0.0-14.0.0.4, 13.0.0-13.1.1.5, 12.1.0-12.1.5, and 11.5.1-11.6.5. In BIG-IP APM 13.1.0 and later, the APM Clients components can be updated independently from BIG-IP software. Client version 7.1.8 (7180.2019.508.705) and later has the fix.

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
Big-ip_access_policy_managerF511.5.2 (including)11.6.5 (including)
Big-ip_access_policy_managerF512.1.0 (including)12.1.5 (including)
Big-ip_access_policy_managerF513.1.0 (including)13.1.3 (excluding)
Big-ip_access_policy_managerF514.0.0 (including)14.0.0.5 (excluding)
Big-ip_access_policy_managerF514.1.0 (including)14.1.2 (excluding)
Big-ip_access_policy_managerF515.0.0 (including)15.0.1 (including)
Big-ip_access_policy_manager_clientF57.1.5 (including)7.1.8 (including)

Potential Mitigations

References