CVE-2023-39447: BIG-IP APM Guided Configuration vulnerability
When BIG-IP APM Guided Configuration is configured, undisclosed sensitive information may be logged in the restnoded log file.
Other sources
When BIG-IP APM Guided Configurations are configured, undisclosed sensitive information may be logged in restnoded log.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-39447?
CVE-2023-39447 is a vulnerability in BIG-IP APM Guided Configurations that allows undisclosed sensitive information to be logged.
How does CVE-2023-39447 affect F5 Big-ip Access Policy Manager?
CVE-2023-39447 affects F5 Big-ip Access Policy Manager versions 15.1.0 to 15.1.8, 16.1.0 to 16.1.4, and 17.0.0.
What is the severity of CVE-2023-39447?
The severity of CVE-2023-39447 is medium (4.4).
How can I fix CVE-2023-39447?
To fix CVE-2023-39447, update your F5 Big-ip Access Policy Manager and F5 Big-ip Guided Configuration to the recommended versions provided by the vendor.
Where can I find more information about CVE-2023-39447?
You can find more information about CVE-2023-39447 at the following reference: [Link](https://my.f5.com/manage/s/article/K47756555).