CVE-2015-7394F5 Big-ip Access Policy Manager vulnerability

CWE-2643 documents3 sources
Severity
9.0CRITICALNVD
EPSS
1.3%
top 20.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 6
Latest updateMay 14

Description

The datastor kernel module in F5 BIG-IP Analytics, APM, ASM, Link Controller, and LTM 11.1.0 before 12.0.0, BIG-IP AAM 11.4.0 before 12.0.0, BIG-IP AFM, PEM 11.3.0 before 12.0.0, BIG-IP Edge Gateway, WebAccelerator, and WOM 11.1.0 through 11.3.0, BIG-IP GTM 11.1.0 through 11.6.0, BIG-IP PSM 11.1.0 through 11.4.1, BIG-IQ Cloud and Security 4.0.0 through 4.5.0, BIG-IQ Device 4.2.0 through 4.5.0, BIG-IQ ADC 4.5.0, and Enterprise Manager 3.0.0 through 3.1.1 allows remote authenticated users to cause

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 8.0 | Impact: 10.0

Affected Packages18 packages

NVDf5/big-ip_edge_gateway4 versions+3
NVDf5/big-ip_link_controller11 versions+10
NVDf5/big-ip_enterprise_manager3.0.0, 3.1.0, 3.1.1+2

🔴Vulnerability Details

2
GHSA
GHSA-pvc2-9ph2-5g8q: The datastor kernel module in F5 BIG-IP Analytics, APM, ASM, Link Controller, and LTM 112022-05-14
CVEList
CVE-2015-7394: The datastor kernel module in F5 BIG-IP Analytics, APM, ASM, Link Controller, and LTM 112015-11-06
CVE-2015-7394 — F5 vulnerability | cvebase