CVE-2018-15310: Infoleak
Published Sep 13, 2018
·Updated
A vulnerability in BIG-IP APM portal access 11.5.1-11.5.7, 11.6.0-11.6.3, and 12.1.0-12.1.3 discloses the BIG-IP software version in rewritten pages.
Affected Software
3 affected components
F5 BIG-IP Access Policy Manager>=11.5.1<=11.5.7
F5 BIG-IP Access Policy Manager>=11.6.0<=11.6.3
F5 BIG-IP Access Policy Manager>=12.1.0<=12.1.3
Event History
Sep 13, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-15310?
CVE-2018-15310 is rated as a medium severity vulnerability due to the potential exposure of sensitive version information.
2
How do I fix CVE-2018-15310?
To fix CVE-2018-15310, upgrade your F5 BIG-IP Access Policy Manager to version 11.5.8, 11.6.4, or 12.1.4 or later.
3
What products are affected by CVE-2018-15310?
CVE-2018-15310 affects F5 BIG-IP APM versions 11.5.1-11.5.7, 11.6.0-11.6.3, and 12.1.0-12.1.3.
4
What is exploited in CVE-2018-15310?
CVE-2018-15310 allows unauthorized disclosure of the BIG-IP software version in rewritten pages.
5
Can CVE-2018-15310 lead to further attacks?
Yes, disclosing the software version through CVE-2018-15310 can aid attackers in identifying potential exploits for that version.