Information disclosure in BIG-IP and BIG-IP APM - #VU27466
Published: April 30, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the BIG-IP APM system may log random data after the APM session ID in the "/var/log/apm" logs. A remote attacker can use the "ACCESS::log" command in an iRule associated with the BIG-IP APM virtual server and cause the characters logged after the APM session ID may leak random information.
Affected software
BIG-IP APM
Remediation
BIG-IP APM - addressed in versions 14.1.2.4, 15.0.1.3, 15.1.0