CVE-2015-8099Improper Input Validation in F5 Big-ip Access Policy Manager

Severity
5.9MEDIUMNVD
EPSS
1.0%
top 22.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 13
Latest updateMay 14

Description

F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF1; BIG-IP AAM 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF1; BIG-IP DNS 12.x before 12.0.0 HF1; BIG-IP Edge Gateway, WebAccelerator, and WOM 11.3.0; BIG-IP GTM 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP PSM 11.3.x and 11.4.x before

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6

Affected Packages21 packages

NVDf5/big-iq_cloud6 versions+5
NVDf5/big-ip_link_controller9 versions+8
NVDf5/big-ip_enterprise_manager3.0.0, 3.1.0, 3.1.1+2

🔴Vulnerability Details

2
GHSA
GHSA-hfqw-6jv9-j568: F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 112022-05-14
CVEList
CVE-2015-8099: F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 112016-05-13
CVE-2015-8099 — Improper Input Validation in F5 | cvebase