On BIG-IP 13.1.0-13.1.1.4, sensitive information is logged into the local log files and/or remote logging targets when restjavad processes an invalid request. Users with access to the log files would be able to view that data.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://support.f5.com/csp/article/K01049383 | vendor advisory |