CVE-2019-6662
published 2019-11-15CVE-2019-6662: On BIG-IP 13.1.0-13.1.1.4, sensitive information is logged into the local log files and/or remote logging targets when restjavad processes an invalid request…
PriorityP433medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.86%
54.4th percentile
On BIG-IP 13.1.0-13.1.1.4, sensitive information is logged into the local log files and/or remote logging targets when restjavad processes an invalid request. Users with access to the log files would be able to view that data.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | >= 13.1.0 < 13.1.1.5 | 13.1.1.5 |
| f5 | big-ip_advanced_firewall_manager | >= 13.1.0 < 13.1.1.5 | 13.1.1.5 |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | >= 13.1.0 < 13.1.1.5 | 13.1.1.5 |
| f5 | big-ip_apm | — | — |
| f5 | big-ip_application_acceleration_manager | >= 13.1.0 < 13.1.1.5 | 13.1.1.5 |
| f5 | big-ip_application_security_manager | >= 13.1.0 < 13.1.1.5 | 13.1.1.5 |
| f5 | big-ip_asm | — | — |
| f5 | big-ip_dns | — | — |
| f5 | big-ip_domain_name_system | >= 13.1.0 < 13.1.1.5 | 13.1.1.5 |
| f5 | big-ip_edge_gateway | — | — |
| f5 | big-ip_edge_gateway | >= 13.1.0 < 13.1.1.5 | 13.1.1.5 |
| f5 | big-ip_fps | — | — |
| f5 | big-ip_fraud_protection_service | >= 13.1.0 < 13.1.1.5 | 13.1.1.5 |
| f5 | big-ip_global_traffic_manager | >= 13.1.0 < 13.1.1.5 | 13.1.1.5 |
| f5 | big-ip_gtm | — | — |
| f5 | big-ip_link_controller | — | — |
| f5 | big-ip_link_controller | >= 13.1.0 < 13.1.1.5 | 13.1.1.5 |
| f5 | big-ip_local_traffic_manager | >= 13.1.0 < 13.1.1.5 | 13.1.1.5 |
| f5 | big-ip_ltm | — | — |
| f5 | big-ip_pem | — | — |
| f5 | big-ip_policy_enforcement_manager | >= 13.1.0 < 13.1.1.5 | 13.1.1.5 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2019-6662: On BIG-IP 13
vendor_f5·2019-11-15·CVSS 6.5
CVE-2019-6662 [MEDIUM] CWE-532 CVE-2019-6662: On BIG-IP 13
CVE-2019-6662: On BIG-IP 13
On BIG-IP 13.1.0-13.1.1.4, sensitive information is logged into the local log files and/or remote logging targets when restjavad processes an invalid request. Users with access to the log files would be able to view that data.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP Analytics, BIG-IP DNS, BIG-IP Edge Gateway, BIG-IP FPS, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IP WebAccelerator
Affected Versions: 13.1.0 - 13.1.1.5
F5 Advisory Articles: K01049383
F5 References: https://support.f5.com/csp/article/K01049383
GHSA
GHSA-j243-5phh-5j8m: On BIG-IP 13
ghsa_unreviewed·2022-05-24
CVE-2019-6662 [MEDIUM] GHSA-j243-5phh-5j8m: On BIG-IP 13
On BIG-IP 13.1.0-13.1.1.4, sensitive information is logged into the local log files and/or remote logging targets when restjavad processes an invalid request. Users with access to the log files would be able to view that data.
Suricata
ET EXPLOIT Possible MySQL cnf overwrite CVE-2016-6662 Attempt
suricata·2016-09-13·CVSS 9.8
CVE-2016-6662 [CRITICAL] ET EXPLOIT Possible MySQL cnf overwrite CVE-2016-6662 Attempt
ET EXPLOIT Possible MySQL cnf overwrite CVE-2016-6662 Attempt
Rule: alert tcp any any -> $HOME_NET 3306 (msg:"ET EXPLOIT Possible MySQL cnf overwrite CVE-2016-6662 Attempt"; flow:established,to_server; content:"|03|"; offset:4; content:"global_log_dir"; nocase; distance:0; content:".cnf"; nocase; distance:0; content:"nmalloc_lib"; fast_pattern; reference:cve,2016-6662; reference:url,legalhackers.com/advisories/MySQL-Exploit-Remote-Root-Code-Execution-Privesc-CVE-2016-6662.html; classtype:attempted-admin; sid:2023202; rev:2; metadata:affected_product MySQL, attack_target Server, created_at 2016_09_13, cve CVE_2016_6662, deployment Datacenter, confidence Medium, signature_severity Major, updated_at 2019_10_08;)
Suricata
ET EXPLOIT Possible MySQL CVE-2016-6662 Attempt
suricata·2016-09-13·CVSS 9.8
CVE-2016-6662 [CRITICAL] ET EXPLOIT Possible MySQL CVE-2016-6662 Attempt
ET EXPLOIT Possible MySQL CVE-2016-6662 Attempt
Rule: alert tcp any any -> $HOME_NET 3306 (msg:"ET EXPLOIT Possible MySQL CVE-2016-6662 Attempt"; flow:established,to_server; content:"|03|"; offset:4; content:"unhex"; nocase; distance:0; content:"67656e6572616c5f6c6f675f66696c65"; distance:0; nocase; content:"2e636e66"; nocase; content:"6e6d616c6c6f635f6c6962"; reference:cve,2016-6662; reference:url,legalhackers.com/advisories/MySQL-Exploit-Remote-Root-Code-Execution-Privesc-CVE-2016-6662.html; classtype:attempted-admin; sid:2023201; rev:1; metadata:affected_product MySQL, attack_target Server, created_at 2016_09_13, cve CVE_2016_6662, deployment Datacenter, confidence Medium, signature_severity Major, updated_at 2019_07_26;)
No public exploits indexed.
No writeups or analysis indexed.
2019-11-15
Published