When the F5 BIG-IP APM 13.0.0-13.1.1 or 12.1.0-12.1.3 renders certain pages (pages with a logon agent or a confirm box), the BIG-IP APM may disclose configuration information such as partition and agent names via URI parameters.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://support.f5.com/csp/article/K23024812 | vendor advisory |
http://www.securitytracker.com/id/1041398 | vdb entry third party advisory |
http://www.securityfocus.com/bid/104932 | vdb entry third party advisory |