CVE-2020-5908 PUBLISHED CVSS 5.5 MEDIUM

In versions bundled with BIG-IP APM 12.1.0-12.1.5 and 11.6.1-11.6.5.2, Edge Client for Linux exposes full session ID in the local log files.

EPSS 0.09% · 25.5th percentile

Risk Scores

CVSS v3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.09%
25.5th percentile

Affected Products

VendorProductVersions
f5big-ip_access_policy_manager11.6.1, 12.1.0
n/aEdge Client for Linux12.1.0-12.1.5, 11.6.1-11.6.5.2

Timeline

References

Open in Interactive Console →