First published: Wed Jul 01 2020(Updated: )
In versions bundled with BIG-IP APM 12.1.0-12.1.5 and 11.6.1-11.6.5.2, Edge Client for Linux exposes full session ID in the local log files.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Access Policy Manager | >=11.6.1<=11.6.5.2 | |
F5 Access Policy Manager | >=12.1.0<=12.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5908 is rated as a high severity vulnerability due to the exposure of sensitive session IDs in log files.
To fix CVE-2020-5908, upgrade to a patched version of BIG-IP APM that is not affected, specifically versions 11.6.5.3 or later and 12.1.5.1 or later.
CVE-2020-5908 can lead to unauthorized access and session hijacking due to the exposure of full session IDs in local log files.
CVE-2020-5908 affects F5 BIG-IP APM versions 12.1.0 through 12.1.5 and 11.6.1 through 11.6.5.2.
There are no specific workarounds for CVE-2020-5908, so upgrading to a secure version is the recommended mitigation.