CVE-2019-6655: Medium severity f5 big-ip application acceleration manager vulnerability
Published Sep 25, 2019
·Updated
On versions 13.0.0-13.1.0.1, 12.1.0-12.1.4.1, 11.6.1-11.6.4, and 11.5.1-11.5.9, BIG-IP platforms where AVR, ASM, APM, PEM, AFM, and/or AAM is provisioned may leak sensitive data.
Affected Software
24 affected components
F5 Big-ip Application Acceleration Manager>=11.5.2<=11.5.9
F5 Big-ip Application Acceleration Manager>=11.6.1<=11.6.4
F5 Big-ip Application Acceleration Manager>=12.1.0<=12.1.4.1
F5 Big-ip Application Acceleration Manager>=13.0.0<=13.1.0.1
F5 BIG-IP Advanced Firewall Manager>=11.5.2<=11.5.9
F5 BIG-IP Advanced Firewall Manager>=11.6.1<=11.6.4
F5 BIG-IP Advanced Firewall Manager>=12.1.0<=12.1.4.1
F5 BIG-IP Advanced Firewall Manager>=13.0.0<=13.1.0.1
F5 BIG-IP Analytics>=11.5.2<=11.5.9
F5 BIG-IP Analytics>=11.6.1<=11.6.4
F5 BIG-IP Analytics>=12.1.0<=12.1.4.1
F5 BIG-IP Analytics>=13.0.0<=13.1.0.1
F5 BIG-IP Access Policy Manager>=11.5.2<=11.5.9
F5 BIG-IP Access Policy Manager>=11.6.1<=11.6.4
F5 BIG-IP Access Policy Manager>=12.1.0<=12.1.4.1
F5 BIG-IP Access Policy Manager>=13.0.0<=13.1.0.1
F5 BIG-IP Application Security Manager>=11.5.2<=11.5.9
F5 BIG-IP Application Security Manager>=11.6.1<=11.6.4
F5 BIG-IP Application Security Manager>=12.1.0<=12.1.4.1
F5 BIG-IP Application Security Manager>=13.0.0<=13.1.0.1
F5 Big-ip Policy Enforcement Manager>=11.5.2<=11.5.9
F5 Big-ip Policy Enforcement Manager>=11.6.1<=11.6.4
F5 Big-ip Policy Enforcement Manager>=12.1.0<=12.1.4.1
F5 Big-ip Policy Enforcement Manager>=13.0.0<=13.1.0.1
Event History
Sep 25, 2019
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-6655?
CVE-2019-6655 has been classified as high severity due to the potential exposure of sensitive data.
2
How do I fix CVE-2019-6655?
To mitigate the effects of CVE-2019-6655, upgrade your affected F5 BIG-IP software to the recommended versions provided by F5.
3
Which versions are affected by CVE-2019-6655?
CVE-2019-6655 affects F5 BIG-IP platforms running versions 11.5.2 to 11.5.9, 11.6.1 to 11.6.4, 12.1.0 to 12.1.4.1, and 13.0.0 to 13.1.0.1.
4
What kind of data is leaked in CVE-2019-6655?
CVE-2019-6655 may leak sensitive data related to application services provisioned on the affected BIG-IP platforms.
5
What components are involved in CVE-2019-6655?
CVE-2019-6655 involves F5 BIG-IP components such as AVR, ASM, APM, PEM, AFM, and AAM.