CVE-2018-15335
published 2018-12-28CVE-2018-15335: When APM 13.0.0-13.1.x is deployed as an OAuth Resource Server, APM becomes a client application to an external OAuth authorization server. In certain cases…
PriorityP430medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
1.43%
70.1th percentile
When APM 13.0.0-13.1.x is deployed as an OAuth Resource Server, APM becomes a client application to an external OAuth authorization server. In certain cases when communication between the BIG-IP APM and the OAuth authorization server is lost, APM may not display the intended message in the failure response
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_access_policy_manager | 13.0.0 – 13.1.1 | — |
| f5 | big-ip_apm | — | — |
| f5_networks_inc | big-ip | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2018-15335: When APM 13
vendor_f5·2018-12-28·CVSS 5.9
CVE-2018-15335 [MEDIUM] CVE-2018-15335: When APM 13
CVE-2018-15335: When APM 13
When APM 13.0.0-13.1.x is deployed as an OAuth Resource Server, APM becomes a client application to an external OAuth authorization server. In certain cases when communication between the BIG-IP APM and the OAuth authorization server is lost, APM may not display the intended message in the failure response
Affected Products: BIG-IP APM
Affected Versions: 13.0.0 - 13.1.1
F5 Advisory Articles: K27617652
F5 References: https://support.f5.com/csp/article/K27617652
GHSA
GHSA-cvpc-h9hw-p85x: When APM 13
ghsa_unreviewed·2022-05-13
CVE-2018-15335 [MEDIUM] GHSA-cvpc-h9hw-p85x: When APM 13
When APM 13.0.0-13.1.x is deployed as an OAuth Resource Server, APM becomes a client application to an external OAuth authorization server. In certain cases when communication between the BIG-IP APM and the OAuth authorization server is lost, APM may not display the intended message in the failure response
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-12-28
Published