QID 378014

Date Published: 2023-03-22

QID 378014: F5 BIG-IP Access Policy Manager (APM) Information Disclosure Vulnerability cve-2018-5544 (K23024812)

When the BIG-IP APM system renders certain pages with a logon agent or a confirm box, the system may disclose configuration information such as partition and agent names via URI parameters. CVE-2018-5544

Vulnerable Component: BIG-IP APM

Affected Versions:
13.0.0 - 13.1.1
12.1.0 - 12.1.3

QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.

This vulnerability allows unauthorized disclosure of information.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    For more information about patch details please refer to K23024812
    Vendor References

    CVEs related to QID 378014

    Software Advisories
    Advisory ID Software Component Link
    K23024812 URL Logo support.f5.com/csp/article/K23024812