VYPR
Medium severity5.3NVD Advisory· Published Feb 20, 2017· Updated May 13, 2026

CVE-2016-6249

CVE-2016-6249

Description

F5 BIG-IP 12.0.0 and 11.5.0 - 11.6.1 REST requests which timeout during user account authentication may log sensitive attributes such as passwords in plaintext to /var/log/restjavad.0.log. It may allow local users to obtain sensitive information by reading these files.

Affected products

1
  • F5 Networks/F5 BIG-IP, REST Framework Loggingv5
    Range: BIG-IP 12.0.0, BIG-IP 11.5.0 - 11.6.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.