CVE-2019-6668: Medium severity f5 access policy manager vulnerability
The BIG-IP APM Edge Client for macOS bundled with BIG-IP APM 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.1.0-13.1.1.5, 12.1.0-12.1.5, and 11.5.1-11.6.5 may allow unprivileged users to access files owned by root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6668?
CVE-2019-6668 is considered a high-severity vulnerability as it can allow unprivileged users to access sensitive files owned by root.
How do I fix CVE-2019-6668?
To remediate CVE-2019-6668, upgrade the BIG-IP APM Edge Client for macOS to a version later than 15.0.1, 14.1.0.5, 14.0.0.4, 13.1.1.5, 12.1.5 and 11.6.5.
Which products are affected by CVE-2019-6668?
CVE-2019-6668 affects F5 BIG-IP Access Policy Manager versions 11.5.1 to 11.6.5, 12.1.0 to 12.1.5, 13.1.0 to 13.1.1.5, 14.0.0 to 14.0.0.4, 14.1.0 to 14.1.0.5, and 15.0.0 to 15.0.1.
Who is impacted by CVE-2019-6668?
Organizations using vulnerable versions of the BIG-IP APM Edge Client for macOS are at risk of unprivileged users accessing restricted files.
Is there a workaround for CVE-2019-6668?
While the best practice is to upgrade to a non-vulnerable version, limiting user access to the affected systems may serve as a temporary workaround until an upgrade is performed.