{"id": "CVE-2016-5021", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N", "authentication": "SINGLE", "integrityImpact": "NONE", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 4.9, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "HIGH", "confidentialityImpact": "HIGH"}, "impactScore": 3.6, "exploitabilityScore": 1.2}]}, "published": "2016-06-24T17:59:01.503", "references": [{"url": "http://www.securitytracker.com/id/1036172", "tags": ["Third Party Advisory", "VDB Entry"], "source": "cve@mitre.org"}, {"url": "https://support.f5.com/kb/en-us/solutions/public/k/99/sol99998454/", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "http://www.securitytracker.com/id/1036172", "tags": ["Third Party Advisory", "VDB Entry"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://support.f5.com/kb/en-us/solutions/public/k/99/sol99998454/", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-200"}]}], "descriptions": [{"lang": "en", "value": "The iControl REST service in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.5.x before 11.5.4, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF3; BIG-IP DNS 12.x before 12.0.0 HF3; BIG-IP GTM 11.5.x before 11.5.4 and 11.6.x before 11.6.1; BIG-IQ Cloud and Security 4.0.0 through 4.5.0; BIG-IQ Device 4.2.0 through 4.5.0; BIG-IQ ADC 4.5.0; BIG-IQ Centralized Management 4.6.0; and BIG-IQ Cloud and Orchestration 1.0.0 allows remote authenticated administrators to obtain sensitive information via unspecified vectors."}, {"lang": "es", "value": "El servicio iControl REST en F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller y PEM 11.5.x en versiones anteriores a 11.5.4, 11.6.x en versiones anteriores a 11.6.1 y 12.x en versiones anteriores a 12.0.0 HF3; BIG-IP DNS 12.x en versiones anteriores a 12.0.0 HF3; BIG-IP GTM 11.5.x en versiones anteriores a 11.5.4 y 11.6.x en versiones anteriores a 11.6.1; BIG-IQ Cloud and Security 4.0.0 hasta la versi\u00f3n 4.5.0; BIG-IQ Device 4.2.0 hasta la versi\u00f3n 4.5.0; BIG-IQ ADC 4.5.0; BIG-IQ Centralized Management 4.6.0 y BIG-IQ Cloud and Orchestration 1.0.0 permite a administradores remotos autenticados obtener informaci\u00f3n sensible a trav\u00e9s de vectores no especificados."}], "lastModified": "2024-11-21T02:53:27.913", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-iq_application_delivery_controller:4.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "222B4DE7-1D3D-40DF-A9EB-EFABDA8FAEA6"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-iq_cloud_and_orchestration:1.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E21D6206-4716-47FE-A733-F18343656E94"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_application_acceleration_manager:11.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0E3D8A24-0B8D-432B-8F06-D0E1642E7C1C"}, {"criteria": "cpe:2.3:a:f5:big-ip_application_acceleration_manager:11.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A4489382-0668-4CFB-BA89-D54762937CEE"}, {"criteria": "cpe:2.3:a:f5:big-ip_application_acceleration_manager:11.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9850D0AA-B173-47B2-9B69-75E6D1FAF490"}, {"criteria": "cpe:2.3:a:f5:big-ip_application_acceleration_manager:11.5.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "281D0B5B-27DF-4E8A-AFC9-D09468F8ECDF"}, {"criteria": "cpe:2.3:a:f5:big-ip_application_acceleration_manager:11.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E5B40837-EC2B-41FB-ACC3-806054EAF28C"}, {"criteria": "cpe:2.3:a:f5:big-ip_application_acceleration_manager:12.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3CA2FA6B-3930-432F-8FB5-E73604CEFE42"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:11.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1C0312FC-8178-46DE-B4EE-00F2895073BA"}, {"criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:11.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BC6C5628-14FF-4D75-B62E-D4B2707C1E3D"}, {"criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:11.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C9E574F6-34B6-45A6-911D-E5347DA22F69"}, {"criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:11.5.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BCF94129-8779-4D68-8DD4-B828CA633746"}, {"criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:11.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CFA77C6B-72DB-4D57-87CF-11F2C7EDB828"}, {"criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:12.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3B62FEC0-EE22-46E6-B811-8AB0EE4C3E2E"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_local_traffic_manager:11.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E5D27D4A-BD5C-4FA9-AA72-F7956298DE06"}, {"criteria": "cpe:2.3:a:f5:big-ip_local_traffic_manager:11.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "12F86EB5-D581-4103-A802-44D968BA8D55"}, {"criteria": "cpe:2.3:a:f5:big-ip_local_traffic_manager:11.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "36F383ED-8CB5-400D-BFDB-BD5B8CD8C7AE"}, {"criteria": "cpe:2.3:a:f5:big-ip_local_traffic_manager:11.5.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E6203A11-82C3-4ABA-94E9-085BFF1A0E4C"}, {"criteria": "cpe:2.3:a:f5:big-ip_local_traffic_manager:11.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2FF5A5F6-4BA3-4276-8679-B5560EACF2E0"}, {"criteria": "cpe:2.3:a:f5:big-ip_local_traffic_manager:12.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "44F1E5E0-BD63-4A4A-BC4E-A1D5495F8B5C"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_global_traffic_manager:11.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0594DBC5-8470-416C-A5EA-E04F5AB2C799"}, {"criteria": "cpe:2.3:a:f5:big-ip_global_traffic_manager:11.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B50BF19F-71B4-47C0-A96E-6EB90FCC6AE7"}, {"criteria": "cpe:2.3:a:f5:big-ip_global_traffic_manager:11.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BD3A3BA6-6F60-45CA-8F52-687B671B077A"}, {"criteria": "cpe:2.3:a:f5:big-ip_global_traffic_manager:11.5.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "202B6870-718C-4F8D-9BAB-7ED6385BF2A7"}, {"criteria": "cpe:2.3:a:f5:big-ip_global_traffic_manager:11.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D7D7863D-B064-4D7A-A66B-C3D3523425FD"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-iq_security:4.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0303BEA3-02EB-4F7C-96C5-29E231832CEA"}, {"criteria": "cpe:2.3:a:f5:big-iq_security:4.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "27CAD4CD-9228-4DE5-A333-2862AC18F24B"}, {"criteria": "cpe:2.3:a:f5:big-iq_security:4.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "283BF2C8-BED6-4FB5-91C0-E53F338F3AF2"}, {"criteria": "cpe:2.3:a:f5:big-iq_security:4.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D98BEE39-FD68-49FC-A2A2-8926FFA4BF51"}, {"criteria": "cpe:2.3:a:f5:big-iq_security:4.4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0003813A-C1A8-4ED1-A04C-7AE961E7FA22"}, {"criteria": "cpe:2.3:a:f5:big-iq_security:4.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DEC1A702-0CCB-48F9-A42E-D8C756DD9D76"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-iq_cloud:4.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D88F8F3B-DD8B-4BB3-BB68-C43583318400"}, {"criteria": "cpe:2.3:a:f5:big-iq_cloud:4.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F677AF16-146D-41A5-ABF3-56DB9C0D6CA6"}, {"criteria": "cpe:2.3:a:f5:big-iq_cloud:4.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CE13DA9F-8460-430E-B939-BF17A7D37A9F"}, {"criteria": "cpe:2.3:a:f5:big-iq_cloud:4.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "70A04EB1-0C2C-4FC0-9E4D-05AFE65503D7"}, {"criteria": "cpe:2.3:a:f5:big-iq_cloud:4.4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CF93E82F-D38C-4D4D-99EB-E334EE163C4E"}, {"criteria": "cpe:2.3:a:f5:big-iq_cloud:4.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A3471D34-A76C-498A-8C45-1553A579A88B"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:11.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1AD2C1D2-103E-4B0F-84AA-999F01E695F0"}, {"criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:11.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "855E91A4-0A0C-4E5C-8019-FB513A793803"}, {"criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:11.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FCCC2092-E109-4FF6-9B85-6C9434269851"}, {"criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:11.5.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8923BB93-96C1-417B-9172-4A81E731EBA2"}, {"criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:11.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "475F0EF8-42CB-4099-9C4A-390F946C4924"}, {"criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:12.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "62B0A70A-D101-443E-A543-5EC35E23D66F"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-iq_centralized_management:4.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "24AEF0B2-7C8C-432C-A840-C2441A70343F"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_domain_name_system:12.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "524B2D05-508C-47FF-94A0-6CC42060E638"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_analytics:11.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A7D226F1-6513-4233-BE20-58D7AB24978F"}, {"criteria": "cpe:2.3:a:f5:big-ip_analytics:11.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B33B2082-E040-4799-A260-BA687ED8614E"}, {"criteria": "cpe:2.3:a:f5:big-ip_analytics:11.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A85766A4-2181-4719-ADCF-4FEA0031DB80"}, {"criteria": "cpe:2.3:a:f5:big-ip_analytics:11.5.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D2E93EE3-DB73-468E-87CA-4D277F283648"}, {"criteria": "cpe:2.3:a:f5:big-ip_analytics:11.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B70D2BD5-8E3F-4B57-84EF-3AF40F6378F1"}, {"criteria": "cpe:2.3:a:f5:big-ip_analytics:12.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D0EDB8E9-E6FB-406E-B1D3-C620F114804C"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_link_controller:11.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "13E6D2CA-CC4F-4317-A842-4DF0693B0CB6"}, {"criteria": "cpe:2.3:a:f5:big-ip_link_controller:11.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AB017D7A-3290-4EF5-9647-B488771A5F32"}, {"criteria": "cpe:2.3:a:f5:big-ip_link_controller:11.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4F316C54-FAE4-48D8-9E40-ED358C30BF24"}, {"criteria": "cpe:2.3:a:f5:big-ip_link_controller:11.5.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AC0F5FD3-45E7-4D55-A3AC-6572FC0682D0"}, {"criteria": "cpe:2.3:a:f5:big-ip_link_controller:11.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5CDEC701-DAB3-4D92-AA67-B886E6693E46"}, {"criteria": "cpe:2.3:a:f5:big-ip_link_controller:12.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E90C12AF-44BA-44A2-89ED-0C2497EEC8A6"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1B6EA0C0-9C26-4A87-98F1-5B317D606ECB"}, {"criteria": "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4D379372-A226-4230-B1F3-04C696518BD8"}, {"criteria": "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "22FAC35D-2803-49B0-9382-F14594B88FC5"}, {"criteria": "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.5.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3C72257B-FF99-4707-A0E3-316D538B1CF6"}, {"criteria": "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CB8D3B87-B8F5-490A-B1D9-04F2EE93EEA3"}, {"criteria": "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:12.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "23FF9627-E561-4CF7-A685-6E33D2F6C98C"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-iq_device:4.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EBA4FC82-F8FB-4F11-94DA-12D280A18E3D"}, {"criteria": "cpe:2.3:a:f5:big-iq_device:4.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CB5D327F-4233-45CE-A557-F7BA717AF057"}, {"criteria": "cpe:2.3:a:f5:big-iq_device:4.4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "99E5F378-E93E-45F6-A445-F2DAB5C423F7"}, {"criteria": "cpe:2.3:a:f5:big-iq_device:4.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A9538F63-3DC9-42CC-87D5-3CA048AE52A6"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3755740D-F1DC-4910-ADDD-9D491515201C"}, {"criteria": "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EA244A7D-F65D-4114-81C8-CE811959EA10"}, {"criteria": "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5EA9F72C-8344-4370-B511-31BEC8BA63E8"}, {"criteria": "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.5.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "96CF015E-C74B-4215-9103-8087BC1D12AB"}, {"criteria": "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B276E4DF-69FC-4158-B93A-781A45605034"}, {"criteria": "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:12.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "532AAF54-64EF-4852-B4F1-D5E660463704"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}