CVE-2020-5908: F5 BIG-IP Access Policy Manager

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In versions bundled with BIG-IP APM 12.1.0-12.1.5 and 11.6.1-11.6.5.2, Edge Client for Linux exposes full session ID in the local log files.

Affected products

  • F5 BIG-IP Access Policy Manager: from 11.6.1, up to and including 11.6.5.2; from 12.1.0, up to and including 12.1.5

Published 2020-07-01. Last modified 2026-06-17.