#VU27466 Information disclosure in BIG-IP and BIG-IP APM
Published: April 30, 2020
BIG-IP
BIG-IP APM
F5 Networks
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the BIG-IP APM system may log random data after the APM session ID in the "/var/log/apm" logs. A remote attacker can use the "ACCESS::log" command in an iRule associated with the BIG-IP APM virtual server and cause the characters logged after the APM session ID may leak random information.