Bug ID 714716: Apmd logs password for acp messages when in debug mode

Last Modified: Sep 13, 2023

Affected Product(s):
BIG-IP APM(all modules)

Known Affected Versions:
11.6.3, 11.6.3.1, 12.0.0, 12.0.0 HF1, 12.1.0 HF1, 12.0.0 HF2, 12.1.0 HF2, 12.0.0 HF3, 12.0.0 HF4, 12.1.1 HF1, 12.1.1 HF2, 12.1.2 HF1, 12.1.2 HF2, 12.1.0, 12.1.1, 12.1.2, 12.1.3, 12.1.3.1, 12.1.3.2, 12.1.3.3, 12.1.3.4, 12.1.3.5, 12.1.3.6, 12.1.3.7, 12.1.4, 13.0.0, 13.0.0 HF1, 13.0.0 HF2, 13.0.0 HF3, 13.0.1, 13.1.0, 13.1.0.1, 13.1.0.2, 13.1.0.3, 13.1.0.4, 13.1.0.5, 13.1.0.6, 13.1.0.7, 13.1.0.8, 13.1.1, 13.1.1.2, 13.1.1.3

Fixed In:
14.0.0, 13.1.1.4, 12.1.4.1, 11.6.3.2

Opened: Apr 11, 2018

Severity: 2-Critical

Related Article: K10248311

Symptoms

Apmd logs password when executing policy via iRule.

Impact

Apmd logs clear text password

Conditions

-- APM is licensed and provisioned -- Executing policy via iRule using iRule command 'ACCESS::policy evaluate'. -- Clear text password is supplied for authentication -- Debug mode active

Workaround

None

Fix Information

Apmd now no longer logs password in debug mode when evaluating policy via iRule.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips