CVE-2017-6139: F5 BIG-IP Access Policy Manager

Medium severity, CVSS 5.9. EPSS: 1.7% chance of exploitation in the next 30 days.

In F5 BIG-IP APM software version 13.0.0 and 12.1.2, under rare conditions, the BIG-IP APM system appends log details when responding to client requests. Details in the log file can vary; customers running debug mode logging with BIG-IP APM are at highest risk.

Affected products

  • F5 BIG-IP Access Policy Manager: version 12.1.2 only; version 13.0.0 only

Published 2017-12-21. Last modified 2026-06-17.