CVE-2020-5908: Medium severity f5 access policy manager vulnerability
Published Jul 1, 2020
·Updated
In versions bundled with BIG-IP APM 12.1.0-12.1.5 and 11.6.1-11.6.5.2, Edge Client for Linux exposes full session ID in the local log files.
Affected Software
2 affected components
F5 BIG-IP Access Policy Manager>=11.6.1<=11.6.5.2
F5 BIG-IP Access Policy Manager>=12.1.0<=12.1.5
Event History
Jul 1, 2020
CVE Published
via MITRE·02:34 PM
Data Sourced
via MITRE·02:34 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-5908?
CVE-2020-5908 is rated as a high severity vulnerability due to the exposure of sensitive session IDs in log files.
2
How do I fix CVE-2020-5908?
To fix CVE-2020-5908, upgrade to a patched version of BIG-IP APM that is not affected, specifically versions 11.6.5.3 or later and 12.1.5.1 or later.
3
What impact does CVE-2020-5908 have on my system?
CVE-2020-5908 can lead to unauthorized access and session hijacking due to the exposure of full session IDs in local log files.
4
Which products are affected by CVE-2020-5908?
CVE-2020-5908 affects F5 BIG-IP APM versions 12.1.0 through 12.1.5 and 11.6.1 through 11.6.5.2.
5
Is there a workaround for CVE-2020-5908?
There are no specific workarounds for CVE-2020-5908, so upgrading to a secure version is the recommended mitigation.