In versions 7.1.5-7.1.8, the BIG-IP Edge Client components in BIG-IP APM, Edge Gateway, and FirePass legacy allow attackers to obtain the full session ID from process memory.
2020-04-30T22:15:12.103
2024-11-21T05:34:46.727
Modified
CVSSv3.1: 6.7 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | f5 | big-ip_access_policy_manager | ≤ 11.6.5 | Yes |
Application | f5 | big-ip_access_policy_manager | ≤ 12.1.5 | Yes |
Application | f5 | big-ip_access_policy_manager | ≤ 13.1.3 | Yes |
Application | f5 | big-ip_access_policy_manager | ≤ 14.1.2 | Yes |
Application | f5 | big-ip_access_policy_manager | ≤ 15.1.0 | Yes |
Application | f5 | big-ip_access_policy_manager_client | ≤ 7.1.8 | Yes |
Application | f5 | big-ip_edge_gateway | ≤ 11.6.5 | Yes |
Application | f5 | big-ip_edge_gateway | ≤ 12.1.5 | Yes |
Application | f5 | big-ip_edge_gateway | ≤ 13.1.3 | Yes |
Application | f5 | big-ip_edge_gateway | ≤ 14.1.2 | Yes |
Application | f5 | big-ip_edge_gateway | ≤ 15.1.0 | Yes |