CVE-2016-1497
The Configuration utility in F5 BIG-IP systems 11.0.x, 11.1.x, 11.2.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4 HF2, 1.6.x before 11.6.1, and 12.0.0 before HF1 allows remote administrators to read Access Policy Manager…
Does this matter?
Lower severity and a low EPSS score (1.53%). Track it; it rarely justifies an emergency change on its own.
Description
The Configuration utility in F5 BIG-IP systems 11.0.x, 11.1.x, 11.2.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4 HF2, 1.6.x before 11.6.1, and 12.0.0 before HF1 allows remote administrators to read Access Policy Manager (APM) access logs via unspecified vectors.
- CVSS 3.0
- 4.9 MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.53% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- f5/big-ip webaccelerator · f5/big-ip link controller · f5/big-ip access policy manager · f5/big-ip application security manager · f5/big-ip domain name system · f5/big-ip global traffic manager · f5/big-ip local traffic manager · f5/big-ip application acceleration manager · f5/big-ip protocol security module · f5/big-ip analytics · f5/big-ip advanced firewall manager · f5/big-ip wan optimization manager · f5/big-ip policy enforcement manager · f5/big-ip edge gateway
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/92671
- http://www.securitytracker.com/id/1036631Third Party Advisory, VDB Entry
- https://support.f5.com/kb/en-us/solutions/public/k/31/sol31925518.htmlVendor Advisory
- http://www.securityfocus.com/bid/92671
- http://www.securitytracker.com/id/1036631Third Party Advisory, VDB Entry
- https://support.f5.com/kb/en-us/solutions/public/k/31/sol31925518.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.