CVE-2019-6662: Medium severity f5 access policy manager vulnerability
On BIG-IP 13.1.0-13.1.1.4, sensitive information is logged into the local log files and/or remote logging targets when restjavad processes an invalid request. Users with access to the log files would be able to view that data.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-6662?
CVE-2019-6662 is a vulnerability on F5 BIG-IP products that allows sensitive information to be logged into local and remote log files.
What software is affected by CVE-2019-6662?
CVE-2019-6662 affects F5 BIG-IP Access Policy Manager, Advanced Firewall Manager, Analytics, Application Acceleration Manager, Application Security Manager, Domain Name System, Edge Gateway, Fraud Protection Service, Global Traffic Manager, Link Controller, Local Traffic Manager, Policy Enforcement Manager, and Webaccelerator.
How severe is CVE-2019-6662?
CVE-2019-6662 has a severity level of 6.5 (Medium).
How can sensitive information be exposed in CVE-2019-6662?
Sensitive information can be exposed in CVE-2019-6662 when restjavad processes an invalid request.
Is there a fix for CVE-2019-6662?
Yes, F5 has released a fix for CVE-2019-6662. Please refer to the F5 support article for more information.