CVE-2016-6249Sensitive Information Exposure in F5 Big-ip Local Traffic Manager

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 80.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 20
Latest updateMay 17

Description

F5 BIG-IP 12.0.0 and 11.5.0 - 11.6.1 REST requests which timeout during user account authentication may log sensitive attributes such as passwords in plaintext to /var/log/restjavad.0.log. It may allow local users to obtain sensitive information by reading these files.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LExploitability: 1.8 | Impact: 3.4

Affected Packages11 packages

NVDf5/big-ip_websafe8 versions+7
NVDf5/big-ip_analytics8 versions+7
NVDf5/big-ip_link_controller8 versions+7

🔴Vulnerability Details

2
GHSA
GHSA-475j-chqr-x6c4: F5 BIG-IP 122022-05-17
CVEList
CVE-2016-6249: F5 BIG-IP 122017-02-20

📋Vendor Advisories

1
F5
CVE-2016-6249: F5 BIG-IP 122017-02-20
CVE-2016-6249 — Sensitive Information Exposure in F5 | cvebase