F5-K000149185: Medium severity f5 big-ip next central manager vulnerability
Published Feb 5, 2025
·Updated
When users log in through the webUI or API using local authentication, BIG-IP Next Central Manager may log sensitive information in the pgaudit log files.
Affected Software
1 affected componentFixes available
F5 BIG-IP Next Central Manager>=20.2.0<=20.2.1
20.3.0
Event History
Feb 5, 2025
Advisory Published
via F5·01:58 PM
Frequently Asked Questions
1
What is the severity of F5-K000149185?
The severity of F5-K000149185 is classified as medium due to the potential exposure of sensitive user information.
2
How do I fix F5-K000149185?
To fix F5-K000149185, you should upgrade to a version of BIG-IP Next Central Manager that is beyond 20.3.0.
3
What types of sensitive information are logged in F5-K000149185?
F5-K000149185 may log sensitive authentication data, including usernames and passwords, in pgaudit log files.
4
Who is affected by F5-K000149185?
F5-K000149185 affects users of F5 BIG-IP Next Central Manager operating between versions 20.2.0 and 20.3.0.
5
When was F5-K000149185 discovered?
F5-K000149185 was identified and disclosed in 2023.