F5-K47756555: Medium severity f5 big-ip access policy manager vulnerability
Published Oct 10, 2023
·Updated
When BIG-IP APM Guided Configuration is configured, undisclosed sensitive information may be logged in the restnoded log file.
Affected Software
9 affected componentsFixes available
F5 BIG-IP (APM)
17.1.0
F5 BIG-IP (APM)>=16.1.0<=16.1.3
16.1.4
F5 BIG-IP (APM)>=15.1.0<=15.1.7
15.1.8
F5 BIG-IP (APM)
F5 BIG-IP (Guided Configuration)
9.0
F5 BIG-IP (Guided Configuration)=8.0
F5 BIG-IP (Guided Configuration)>=7.0<=7.7
F5 BIG-IP (Guided Configuration)=6.0
F5 BIG-IP (Guided Configuration)
Event History
Oct 10, 2023
Advisory Published
via F5·10:18 AM
Frequently Asked Questions
1
What is the severity of F5-K47756555?
The severity of F5-K47756555 is critical due to the potential exposure of sensitive information in the logs.
2
How do I fix F5-K47756555?
To fix F5-K47756555, update to the latest versions of the affected F5 BIG-IP software as outlined in the advisory.
3
Which versions of F5 BIG-IP are affected by F5-K47756555?
F5-K47756555 affects multiple versions including 17.1.0, 16.1.4, 15.1.8, and several others across BIG-IP (APM) and BIG-IP (Guided Configuration).
4
What information is exposed by the F5-K47756555 vulnerability?
F5-K47756555 may expose undisclosed sensitive information logged in the restnoded log file.
5
Is there a workaround for F5-K47756555 before applying a patch?
There is no specific workaround for F5-K47756555, so applying the recommended patch is necessary to mitigate the risk.