Vulnerability Description
The Configuration utility in F5 BIG-IP systems 11.0.x, 11.1.x, 11.2.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4 HF2, 1.6.x before 11.6.1, and 12.0.0 before HF1 allows remote administrators to read Access Policy Manager (APM) access logs via unspecified vectors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| F5 | Big-Ip Webaccelerator | 11.0.0 |
| F5 | Big-Ip Link Controller | 11.0.0 |
| F5 | Big-Ip Access Policy Manager | 11.0.0 |
| F5 | Big-Ip Application Security Manager | 11.0.0 |
| F5 | Big-Ip Domain Name System | 12.0.0 |
| F5 | Big-Ip Global Traffic Manager | 11.0.0 |
| F5 | Big-Ip Local Traffic Manager | 11.0.0 |
| F5 | Big-Ip Application Acceleration Manager | 11.4.0 |
| F5 | Big-Ip Protocol Security Module | 11.0.0 |
| F5 | Big-Ip Analytics | 11.0.0 |
| F5 | Big-Ip Advanced Firewall Manager | 11.2.1 |
| F5 | Big-Ip Wan Optimization Manager | 11.0.0 |
| F5 | Big-Ip Policy Enforcement Manager | 11.3.0 |
| F5 | Big-Ip Edge Gateway | 11.0.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/92671
- http://www.securitytracker.com/id/1036631Third Party AdvisoryVDB Entry
- https://support.f5.com/kb/en-us/solutions/public/k/31/sol31925518.htmlVendor Advisory
- http://www.securityfocus.com/bid/92671
- http://www.securitytracker.com/id/1036631Third Party AdvisoryVDB Entry
- https://support.f5.com/kb/en-us/solutions/public/k/31/sol31925518.htmlVendor Advisory
FAQ
What is CVE-2016-1497?
CVE-2016-1497 is a vulnerability with a CVSS score of 4.9 (MEDIUM). The Configuration utility in F5 BIG-IP systems 11.0.x, 11.1.x, 11.2.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4 HF2, 1.6.x before 11.6.1, and 12.0.0 before HF1 allows...
How severe is CVE-2016-1497?
CVE-2016-1497 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-1497?
Check the references section above for vendor advisories and patch information. Affected products include: F5 Big-Ip Webaccelerator, F5 Big-Ip Link Controller, F5 Big-Ip Access Policy Manager, F5 Big-Ip Application Security Manager, F5 Big-Ip Domain Name System.