CVE-2017-0301
published 2017-12-21CVE-2017-0301: In F5 BIG-IP APM software versions 11.5.0, 11.5.1, 11.5.2, 11.5.3, 11.5.4, 11.6.0, 11.6.1, 12.0.0, 12.1.0, 12.1.1 and 12.1.2 BIG-IP APM portal access requests…
PriorityP434high7.6CVSS 3.0
AVAACHPRLUIRSCCHIHAH
EPSS
0.53%
41.5th percentile
In F5 BIG-IP APM software versions 11.5.0, 11.5.1, 11.5.2, 11.5.3, 11.5.4, 11.6.0, 11.6.1, 12.0.0, 12.1.0, 12.1.1 and 12.1.2 BIG-IP APM portal access requests do not return the intended resources in some cases. This may allow access to internal BIG-IP APM resources, however the application resources and backend servers are unaffected.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_apm | — | — |
| f5_networks_inc | big-ip_apm | — | — |
| f5_networks_inc | big-ip_apm | — | — |
| f5_networks_inc | big-ip_apm | — | — |
CVSS provenance
nvdv3.07.6HIGHCVSS:3.0/AV:A/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
nvdv2.04.0MEDIUMAV:A/AC:H/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2v8v-crm8-62x6: In F5 BIG-IP APM software versions 11
ghsa_unreviewed·2022-05-13
CVE-2017-0301 [HIGH] GHSA-2v8v-crm8-62x6: In F5 BIG-IP APM software versions 11
In F5 BIG-IP APM software versions 11.5.0, 11.5.1, 11.5.2, 11.5.3, 11.5.4, 11.6.0, 11.6.1, 12.0.0, 12.1.0, 12.1.1 and 12.1.2 BIG-IP APM portal access requests do not return the intended resources in some cases. This may allow access to internal BIG-IP APM resources, however the application resources and backend servers are unaffected.
F5
CVE-2017-0301: In F5 BIG-IP APM software versions 11
vendor_f5·2017-12-21·CVSS 7.6
CVE-2017-0301 [HIGH] CVE-2017-0301: In F5 BIG-IP APM software versions 11
CVE-2017-0301: In F5 BIG-IP APM software versions 11
In F5 BIG-IP APM software versions 11.5.0, 11.5.1, 11.5.2, 11.5.3, 11.5.4, 11.6.0, 11.6.1, 12.0.0, 12.1.0, 12.1.1 and 12.1.2 BIG-IP APM portal access requests do not return the intended resources in some cases. This may allow access to internal BIG-IP APM resources, however the application resources and backend servers are unaffected.
Affected Products: BIG-IP APM
Affected Versions: 11.5.0; 11.5.1; 11.5.2; 11.5.3; 11.5.4; 11.6.0; 11.6.1; 12.0.0; 12.1.0; 12.1.1
F5 Advisory Articles: K54358225
F5 References: https://support.f5.com/csp/article/K54358225
No detection rules found.
No public exploits indexed.
2017-12-21
Published