CVE-2016-9244
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized memory. A remote attacker may exploit this vulnerability to obtain Secure Sockets Layer (SSL) session IDs from other sessions. It is possible that other data from uninitialized memory may be returned as well.
Affected (115)
Products: F5: Big Ip Local Traffic Manager, Big Ip Application Acceleration Manager, Big Ip Advanced Firewall Manager, Big Ip Analytics, Big Ip Access Policy Manager, Big Ip Application Security Manager, Big Ip Global Traffic Manager, Big Ip Link Controller, Big Ip Policy Enforcement Manager, Big Ip Protocol Security Module
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.4.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.4.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.4.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.4.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.4.0 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.4.0 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.4.0 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.4.0 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.4.0 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.4.0 |
References (16)
Source: f5sirt@f5.com
Source: f5sirt@f5.com
Source: f5sirt@f5.com
Source: f5sirt@f5.com
Source: f5sirt@f5.com
Source: f5sirt@f5.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.