CVE-2019-6656: F5 BIG-IP Access Policy Manager

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

BIG-IP APM Edge Client before version 7.1.8 (7180.2019.508.705) logs the full apm session ID in the log files. Vulnerable versions of the client are bundled with BIG-IP APM versions 15.0.0-15.0.1, 14,1.0-14.1.0.6, 14.0.0-14.0.0.4, 13.0.0-13.1.1.5, 12.1.0-12.1.5, and 11.5.1-11.6.5. In BIG-IP APM 13.1.0 and later, the APM Clients components can be updated independently from BIG-IP software. Client version 7.1.8 (7180.2019.508.705) and later has the fix.

Affected products

  • F5 BIG-IP Access Policy Manager: from 11.5.2, up to and including 11.6.5; from 12.1.0, up to and including 12.1.5; from 13.1.0, before 13.1.3 (fixed in 13.1.3); from 14.0.0, before 14.0.0.5 (fixed in 14.0.0.5); from 14.1.0, before 14.1.2 (fixed in 14.1.2); from 15.0.0, up to and including 15.0.1
  • F5 BIG-IP Access Policy Manager Client: from 7.1.5, up to and including 7.1.8

Published 2019-09-25. Last modified 2026-06-17.