cbcvebase.
CVE-2023-22418
published 2023-02-01

CVE-2023-22418: On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.7, 14.1.x before 14.1.5.3, and all versions of 13.1.x, an open redirect…

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.7, 14.1.x before 14.1.5.3, and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy. This vulnerability allows an unauthenticated malicious attacker to build an open redirect URI. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected

73 ranges· showing 25
VendorProductVersion rangeFixed in
f5big-ip>= 13.1.0 < **
f5big-ip>= 14.1.0 < 14.1.5.314.1.5.3
f5big-ip>= 15.1.0 < 15.1.715.1.7
f5big-ip>= 16.1.0 < 16.1.3.316.1.3.3
f5big-ip>= 17.0.0 < 17.0.0.217.0.0.2
f5big-ip_aam
f5big-ip_access_policy_manager13.1.0 – 13.1.5
f5big-ip_access_policy_manager>= 14.1.0 < 14.1.5.314.1.5.3
f5big-ip_access_policy_manager>= 15.1.0 < 15.1.715.1.7
f5big-ip_access_policy_manager>= 16.1.0 < 16.1.3.316.1.3.3
f5big-ip_access_policy_manager>= 17.0.0 < 17.0.0.217.0.0.2
f5big-ip_advanced_firewall_manager13.1.0 – 13.1.5
f5big-ip_advanced_firewall_manager>= 14.1.0 < 14.1.5.314.1.5.3
f5big-ip_advanced_firewall_manager>= 15.1.0 < 15.1.715.1.7
f5big-ip_advanced_firewall_manager>= 16.1.0 < 16.1.3.316.1.3.3
f5big-ip_advanced_firewall_manager>= 17.0.0 < 17.0.0.217.0.0.2
f5big-ip_afm
f5big-ip_analytics
f5big-ip_analytics13.1.0 – 13.1.5
f5big-ip_analytics>= 14.1.0 < 14.1.5.314.1.5.3
f5big-ip_analytics>= 15.1.0 < 15.1.715.1.7
f5big-ip_analytics>= 16.1.0 < 16.1.3.316.1.3.3
f5big-ip_analytics>= 17.0.0 < 17.0.0.217.0.0.2
f5big-ip_apm
f5big-ip_application_acceleration_manager13.1.0 – 13.1.5