F5 Big-Ip Access Policy Manager vulnerabilities
591 known vulnerabilities affecting f5/big-ip_access_policy_manager.
Total CVEs
591
CISA KEV
12
actively exploited
Public exploits
20
Exploited in wild
11
Severity breakdown
CRITICAL43HIGH321MEDIUM219LOW8
Vulnerabilities
Page 13 of 30
CVE-2021-22974HIGHCVSS 7.5≥ 13.1.0, < 13.1.3.6≥ 14.1.0, < 14.1.3.1+2 more2021-02-12
CVE-2021-22974 [HIGH] CVE-2021-22974: On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, and 13.1.x b
On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6 and all versions of BIG-IQ 7.x and 6.x, an authenticated attacker with access to iControl REST over the control plane may be able to take advantage of a race condition to execute commands with an elevated privilege level. This vulnerability is du
nvd
CVE-2021-22980HIGHCVSS 7.8≥ 11.6.1, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+4 more2021-02-12
CVE-2021-22980 [HIGH] CWE-426 CVE-2021-22980: In Edge Client version 7.2.x before 7.2.1.1, 7.1.9.x before 7.1.9.8, and 7.1.x-7.1.8.x before 7.1.8.
In Edge Client version 7.2.x before 7.2.1.1, 7.1.9.x before 7.1.9.8, and 7.1.x-7.1.8.x before 7.1.8.5, an untrusted search path vulnerability in the BIG-IP APM Client Troubleshooting Utility (CTU) for Windows could allow an attacker to load a malicious DLL library from its current directory. User interaction is required to exploit this vulnerability i
nvd
CVE-2021-22977HIGHCVSS 7.5≥ 14.1.0, < 14.1.3.1≥ 16.0.0, < 16.0.1.1+1 more2021-02-12
CVE-2021-22977 [HIGH] CVE-2021-22977: On BIG-IP version 16.0.0-16.0.1 and 14.1.2.4-14.1.3, cooperation between malicious HTTP client code
On BIG-IP version 16.0.0-16.0.1 and 14.1.2.4-14.1.3, cooperation between malicious HTTP client code and a malicious server may cause TMM to restart and generate a core file. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
cvelistv5nvd
CVE-2021-22981MEDIUMCVSS 4.8≥ 11.6.1, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+1 more2021-02-12
CVE-2021-22981 [MEDIUM] CVE-2021-22981: On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the ma
On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiation that is mitigated by the Extended Master Secret (EMS) extension defined in RFC 7627. TLS connections that do not use EMS are vulnerable to man-in-the-middle attacks during renegotiation. Note: Software versions which have reached End o
cvelistv5nvd
CVE-2021-22979MEDIUMCVSS 6.1≥ 12.1.0, ≤ 12.1.5≥ 13.1.0, < 13.1.3.5+4 more2021-02-12
CVE-2021-22979 [MEDIUM] CWE-79 CVE-2021-22979: On BIG-IP version 16.0.x before 16.0.1, 15.1.x before 15.1.1, 14.1.x before 14.1.2.8, 13.1.x before
On BIG-IP version 16.0.x before 16.0.1, 15.1.x before 15.1.1, 14.1.x before 14.1.2.8, 13.1.x before 13.1.3.5, and all 12.1.x versions, a reflected Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility when Fraud Protection Service is provisioned and allows an attacker to execute JavaScript in the co
cvelistv5nvd
CVE-2020-27723HIGHCVSS 7.5≥ 13.1.0, < 13.1.3.5≥ 14.1.0, < 14.1.3.1+1 more2020-12-24
CVE-2020-27723 [HIGH] CVE-2020-27723: In versions 14.1.0-14.1.3 and 13.1.0-13.1.3.4, a BIG-IP APM virtual server processing PingAccess req
In versions 14.1.0-14.1.3 and 13.1.0-13.1.3.4, a BIG-IP APM virtual server processing PingAccess requests may lead to a restart of the Traffic Management Microkernel (TMM) process.
nvd
CVE-2020-27715HIGHCVSS 7.5≥ 14.1.0, < 14.1.3.1≥ 15.0.0, < 15.1.1+1 more2020-12-24
CVE-2020-27715 [HIGH] CVE-2020-27715: On BIG-IP 15.1.0-15.1.0.5 and 14.1.0-14.1.3, crafted TLS request to the BIG-IP management interface
On BIG-IP 15.1.0-15.1.0.5 and 14.1.0-14.1.3, crafted TLS request to the BIG-IP management interface via port 443 can cause high (~100%) CPU utilization by the httpd daemon.
cvelistv5nvd
CVE-2020-27716HIGHCVSS 7.5≥ 11.6.1, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+3 more2020-12-24
CVE-2020-27716 [HIGH] CVE-2020-27716: On versions 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.5, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, w
On versions 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.5, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, when a BIG-IP APM virtual server processes traffic of an undisclosed nature, the Traffic Management Microkernel (TMM) stops responding and restarts.
nvd
CVE-2020-27719MEDIUMCVSS 6.1≥ 14.1.0, < 14.1.3.1≥ 15.0.0, < 15.1.1+2 more2020-12-24
CVE-2020-27719 [MEDIUM] CWE-79 CVE-2020-27719: On BIG-IP 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.3, a cross-site scripting (XSS) vulnerab
On BIG-IP 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.3, a cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility.
cvelistv5nvd
CVE-2020-27726MEDIUMCVSS 6.1≥ 12.1.0, ≤ 12.1.5≥ 13.1.0, < 13.1.3.5+3 more2020-12-24
CVE-2020-27726 [MEDIUM] CWE-79 CVE-2020-27726: In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.2, a
In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.2, a reflected cross-site scripting (XSS) vulnerability exists in the resource information page for authenticated users when a full webtop is configured on the BIG-IP APM system.
nvd
CVE-2020-27722MEDIUMCVSS 6.5≥ 13.1.0, < 13.1.3.5≥ 14.1.0, < 14.1.3.1+1 more2020-12-24
CVE-2020-27722 [MEDIUM] CWE-400 CVE-2020-27722: In BIG-IP APM versions 15.0.0-15.0.1.3, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, under certain conditions
In BIG-IP APM versions 15.0.0-15.0.1.3, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, under certain conditions, the VDI plugin does not observe plugin flow-control protocol causing excessive resource consumption.
nvd
CVE-2020-27724MEDIUMCVSS 6.5≥ 11.6.1, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+5 more2020-12-24
CVE-2020-27724 [MEDIUM] CWE-400 CVE-2020-27724: In BIG-IP APM versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.3, 13.1.0-13.1
In BIG-IP APM versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, on systems running more than one TMM instance, authenticated VPN users may consume excessive resources by sending specially-crafted malicious traffic over the tunnel.
nvd
CVE-2020-27727MEDIUMCVSS 4.9≥ 13.1.0, < 13.1.3.5≥ 14.1.0, < 14.1.3.1+3 more2020-12-24
CVE-2020-27727 [MEDIUM] CWE-20 CVE-2020-27727: On BIG-IP version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, when an auth
On BIG-IP version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, when an authenticated administrative user installs RPMs using the iAppsLX REST installer, the BIG-IP system does not sufficiently validate user input, allowing the user read access to the filesystem.
cvelistv5nvd
CVE-2020-27729MEDIUMCVSS 6.1≥ 11.6.1, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+4 more2020-12-24
CVE-2020-27729 [MEDIUM] CWE-601 CVE-2020-27729: In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 1
In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, an undisclosed link on the BIG-IP APM virtual server allows a malicious user to build an open redirect URI.
nvd
CVE-2020-5948CRITICALCVSS 9.6≥ 13.1.0, < 13.1.3.5≥ 14.1.0, < 14.1.2.8+3 more2020-12-11
CVE-2020-5948 [CRITICAL] CWE-79 CVE-2020-5948: On BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5
On BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete compromise of the BIG-IP system if the victim user is granted the admin role.
cvelistv5nvd
CVE-2020-27713HIGHCVSS 7.5v13.1.3.42020-12-11
CVE-2020-27713 [HIGH] CVE-2020-27713: In certain configurations on version 13
In certain configurations on version 13.1.3.4, when a BIG-IP AFM HTTP security profile is applied to a virtual server and the BIG-IP system receives a request with specific characteristics, the connection is reset and the Traffic Management Microkernel (TMM) leaks memory.
cvelistv5
CVE-2020-5949HIGHCVSS 7.5≥ 13.1.0, < 13.1.3.5≥ 14.0.0, < 14.1.0+1 more2020-12-11
CVE-2020-5949 [HIGH] CVE-2020-5949: On BIG-IP versions 14.0.0-14.0.1 and 13.1.0-13.1.3.4, certain traffic pattern sent to a virtual serv
On BIG-IP versions 14.0.0-14.0.1 and 13.1.0-13.1.3.4, certain traffic pattern sent to a virtual server configured with an FTP profile can cause the FTP channel to break.
cvelistv5nvd
CVE-2020-5950MEDIUMCVSS 5.3v14.1.0-14.1.2.62020-12-11
CVE-2020-5950 [MEDIUM] CVE-2020-5950: On BIG-IP 14
On BIG-IP 14.1.0-14.1.2.6, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete compromise of the BIG-IP system if the victim user is granted the admin role.
cvelistv5
CVE-2020-5947MEDIUMCVSS 4.3≥ 15.0.0, < 15.1.2≥ 16.0.0, < 16.0.12020-11-19
CVE-2020-5947 [MEDIUM] CVE-2020-5947: In versions 16.0.0-16.0.0.1 and 15.1.0-15.1.1, on specific BIG-IP platforms, attackers may be able t
In versions 16.0.0-16.0.0.1 and 15.1.0-15.1.1, on specific BIG-IP platforms, attackers may be able to obtain TCP sequence numbers from the BIG-IP system that can be reused in future connections with the same source and destination port and IP numbers. Only these platforms are affected: BIG-IP 2000 series (C112), BIG-IP 4000 series (C113), BIG-IP i2000 series
nvd
CVE-2020-5945HIGHCVSS 8.4≥ 14.1.0, < 14.1.2.8≥ 15.1.0, < 15.1.1+2 more2020-11-05
CVE-2020-5945 [HIGH] CWE-79 CVE-2020-5945: In BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.2.7, undisclosed TMUI page cont
In BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.2.7, undisclosed TMUI page contains a stored cross site scripting vulnerability (XSS). The issue allows a minor privilege escalation for resource admin to escalate to full admin.
cvelistv5nvd