CVE-2015-8021

Severity
4.3MEDIUM
EPSS
0.1%
top 70.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 12
Latest updateMay 17

Description

Incomplete blacklist vulnerability in the Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, Link Controller, and PSM 11.x before 11.2.1 HF11, 11.3.x, 11.4.0 before HF8, and 11.4.1 before HF6; BIG-IP AAM 11.4.0 before HF8 and 11.4.1 before HF6; BIG-IP AFM and PEM 11.3.x, 11.4.0 before HF8, and 11.4.1 before HF6; and BIG-IP Edge Gateway, WebAccelerator, and WOM 11.x before 11.2.1 HF11 and 11.3.0 allows remote authenticated users to upload files via uploadImage.php.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages13 packages

NVDf5/big-ip_edge_gateway5 versions+4
NVDf5/big-ip_link_controller7 versions+6
NVDf5/big-ip_analytics7 versions+6
NVDf5/big-ip_webaccelerator5 versions+4

🔴Vulnerability Details

2
GHSA
GHSA-7v4p-8gjr-6xq3: Incomplete blacklist vulnerability in the Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, Link Controller, and PSM 112022-05-17
CVEList
CVE-2015-8021: Incomplete blacklist vulnerability in the Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, Link Controller, and PSM 112016-04-12
CVE-2015-8021 (MEDIUM CVSS 4.3) | Incomplete blacklist vulnerability | cvebase.io