CVE-2016-3686
—CVSS 3.0
5.9 medium
EPSS
2%p73
Published
()
Modified
Description
The Single Sign-On (SSO) feature in F5 BIG-IP APM 11.x before 11.6.0 HF6 and BIG-IP Edge Gateway 11.0.0 through 11.3.0 might allow remote attackers to obtain sensitive SessionId information by leveraging access to the Location HTTP header in a redirect.
- Vendors
- f5
- Products
- big-ip edge gateway, big-ip access policy manager
- Weakness
- CWE-200
- Vector
- CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.