CVE-2017-6139: Medium severity f5 access policy manager vulnerability
In F5 BIG-IP APM software version 13.0.0 and 12.1.2, under rare conditions, the BIG-IP APM system appends log details when responding to client requests. Details in the log file can vary; customers running debug mode logging with BIG-IP APM are at highest risk.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6139?
CVE-2017-6139 is considered a medium severity vulnerability that may expose sensitive information through log details.
How do I fix CVE-2017-6139?
To fix CVE-2017-6139, it's recommended to upgrade to a patched version of F5 BIG-IP APM that is not affected.
What products are affected by CVE-2017-6139?
CVE-2017-6139 affects F5 BIG-IP APM versions 12.1.2 and 13.0.0.
What risks are associated with enabling debug mode on F5 BIG-IP APM in relation to CVE-2017-6139?
Enabling debug mode on F5 BIG-IP APM increases the risk of leaking sensitive information through appended log details.
What is the nature of the vulnerability described in CVE-2017-6139?
CVE-2017-6139 involves the inadvertent exposure of log information when the BIG-IP APM responds to client requests under specific conditions.