First published: Wed Aug 14 2024(Updated: )
Undisclosed requests to BIG-IP iControl REST can lead to an information leak of user account names.
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP and BIG-IQ Centralized Management | =17.1.0 | 17.1.1 |
F5 BIG-IP and BIG-IQ Centralized Management | >=16.1.0<=16.1.4 | 16.1.5 |
F5 BIG-IP and BIG-IQ Centralized Management | >=15.1.0<=15.1.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of F5-K10438187 is considered moderate due to the potential information leak of user account names.
To fix F5-K10438187, apply the recommended updates provided by F5 for the affected BIG-IP versions.
F5-K10438187 affects BIG-IP versions 15.1.0 to 15.1.10, 16.1.0 to 16.1.4, and exactly 17.1.0.
F5-K10438187 is an information leak vulnerability which may expose user account names.
At this time, it is recommended to upgrade to a patched version as no official workarounds have been provided for F5-K10438187.