CVE-2020-5902 is an F5 BIG-IP Traffic Management User Interface (TMUI) remote code execution issue. CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, marked it as having known ransomware campaign use, and set the remediation expectation to apply updates per vendor instructions.
CVE-2016-6249 is an information disclosure issue in F5 BIG-IP. When certain REST authentication requests time out, sensitive attributes such as passwords may be written in plaintext to /var/log/restjavad.0.log. A local user with access to the appliance can then read the log file and recover that data. The NVD assigns a medium-severity score and maps the weakness to CWE-200.
CVE-2016-9244, commonly referred to as Ticketbleed, is a confidentiality issue in F5 BIG-IP when a virtual server uses a Client SSL profile with the non-default Session Tickets option enabled. A remote attacker can cause up to 31 bytes of uninitialized memory to be returned, which may expose SSL session IDs from other sessions and possibly additional data. NVD rates the issue CVSS 7.5 HIGH.
CVE-2016-9249 is a denial-of-service issue affecting F5 BIG-IP deployments with TCP Fast Open enabled on a virtual server. According to the official NVD description, an undisclosed traffic pattern can cause the Traffic Management Microkernel (TMM) to restart, interrupting traffic handling and availability. The CVE was published on 2017-01-31 and is rated HIGH in the supplied corpus.