Description
The web application uses an F5 BIG-IP load balancer. It sets a cookie that may include sensitive information about backend servers. An unauthenticated attacker may decode the cookie and get this information
Remediation
Consult Web references for more information about the possible improvements
References
K6917: Overview of BIG-IP persistence cookie encoding
K14784: Configuring cookie encryption within the HTTP profile
Related Vulnerabilities
PostgreSQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-5288)
Zend Framework local file disclosure via XXE injection
WordPress Plugin File Manager Information Disclosure (6.4)
WeBid Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3815)