CVE-2016-3686: F5 BIG-IP Access Policy Manager

Medium severity, CVSS 5.9. EPSS: 1.5% chance of exploitation in the next 30 days.

The Single Sign-On (SSO) feature in F5 BIG-IP APM 11.x before 11.6.0 HF6 and BIG-IP Edge Gateway 11.0.0 through 11.3.0 might allow remote attackers to obtain sensitive SessionId information by leveraging access to the Location HTTP header in a redirect.

Affected products

  • F5 BIG-IP Access Policy Manager: version 11.0.0 only; version 11.1.0 only; version 11.2.0 only; version 11.2.1 only; version 11.3.0 only; version 11.4.0 only; …
  • F5 BIG-IP Edge Gateway: version 11.0.0 only; version 11.1.0 only; version 11.2.0 only; version 11.2.1 only; version 11.3.0 only

Published 2016-04-13. Last modified 2026-06-17.