CVE-2019-19150: Medium severity f5 access policy manager vulnerability
On versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, the BIG-IP APM system logs the client-session-id when a per-session policy is attached to the virtual server with debug logging enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19150?
CVE-2019-19150 is considered a medium severity vulnerability as it can lead to exposure of sensitive client session identifiers.
How do I fix CVE-2019-19150?
To remediate CVE-2019-19150, upgrade the F5 BIG-IP Access Policy Manager to a version that is not vulnerable, specifically versions above 15.0.1.1, 14.1.2, 14.0.1.1, 13.1.3.2, 12.1.5, and 11.6.5.1.
What versions are affected by CVE-2019-19150?
CVE-2019-19150 affects F5 BIG-IP Access Policy Manager versions between 11.6.1 and 11.6.5, 12.1.0 and 12.1.5, 13.1.0 and 13.1.3.1, 14.0.0 and 14.1.2, and 15.0.0 and 15.0.1.1.
What are the potential risks associated with CVE-2019-19150?
The potential risks include unauthorized access to client session identifiers that may lead to session hijacking or impersonation.
Is there a workaround for CVE-2019-19150?
Disabling debug logging for the virtual server is a possible workaround to mitigate the exposure while planning for an upgrade.