Medium severity5.3NVD Advisory· Published Feb 20, 2017· Updated May 13, 2026
CVE-2016-6249
CVE-2016-6249
Description
F5 BIG-IP 12.0.0 and 11.5.0 - 11.6.1 REST requests which timeout during user account authentication may log sensitive attributes such as passwords in plaintext to /var/log/restjavad.0.log. It may allow local users to obtain sensitive information by reading these files.
Affected products
1- F5 Networks/F5 BIG-IP, REST Framework Loggingv5Range: BIG-IP 12.0.0, BIG-IP 11.5.0 - 11.6.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- support.f5.com/csp/article/K12685114nvdVendor Advisory
- www.securitytracker.com/id/1037873nvd
News mentions
0No linked articles in our index yet.