cbcvebase.

F5 Big-Ip Access Policy Manager vulnerabilities

623 known vulnerabilities affecting f5/big-ip_access_policy_manager.

Total CVEs
623
CISA KEV
12
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL44HIGH336MEDIUM236LOW7

Vulnerabilities

Page 20 of 32
CVE-2021-22980P3HIGHCVSS 7.8≥ 11.6.1, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+4 more2021-02-12
CVE-2021-22980 [HIGH] CWE-426 CVE-2021-22980: In Edge Client version 7.2.x before 7.2.1.1, 7.1.9.x before 7.1.9.8, and 7.1.x-7.1.8.x before 7.1.8. In Edge Client version 7.2.x before 7.2.1.1, 7.1.9.x before 7.1.9.8, and 7.1.x-7.1.8.x before 7.1.8.5, an untrusted search path vulnerability in the BIG-IP APM Client Troubleshooting Utility (CTU) for Windows could allow an attacker to load a malicious DLL library from its current directory. User interaction is required to exploit this vulnerability i
nvd
CVE-2019-6614P3MEDIUMCVSS 6.5≥ 12.1.0, < 12.1.4.1≥ 13.0.0, < 13.1.1.5+1 more2019-05-03
CVE-2019-6614 [MEDIUM] CVE-2019-6614: On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, internal methods used to prevent arbi On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, internal methods used to prevent arbitrary file overwrites in Appliance Mode were not fully effective. An authenticated attacker with a high privilege level may be able to bypass protections implemented in appliance mode to overwrite arbitrary system files.
nvd
CVE-2022-23023P3MEDIUMCVSS 6.5≥ 12.1.0, ≤ 12.1.5≥ 13.1.0, ≤ 13.1.4+3 more2022-01-25
CVE-2022-23023 [MEDIUM] CWE-400 CVE-2022-23023: On BIG-IP version 16.1.x before 16.1.2.1, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all vers On BIG-IP version 16.1.x before 16.1.2.1, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, and BIG-IQ all versions of 8.x and 7.x, undisclosed requests by an authenticated iControl REST user can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (E
nvd
CVE-2022-23014P3MEDIUMCVSS 6.5≥ 15.1.0, < 15.1.4.1≥ 16.1.0, < 16.1.22022-01-25
CVE-2022-23014 [MEDIUM] CWE-20 CVE-2022-23014: On versions 16.1.x before 16.1.2 and 15.1.x before 15.1.4.1, when BIG-IP APM portal access is config On versions 16.1.x before 16.1.2 and 15.1.x before 15.1.4.1, when BIG-IP APM portal access is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2024-21782P3MEDIUMCVSS 6.7≥ 15.1.0, < 15.1.9≥ 16.1.0, < 16.1.4+1 more2024-02-14
CVE-2024-21782 [MEDIUM] CVE-2024-21782: BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility but do not have access to Advanced shell (bash) can execute arbitrary commands with a specially crafted command string. This vulnerability is due to an incomplete fix for CVE-2020-5873. Note: Software versions which have reached End of Techni
nvd
CVE-2022-34851P3MEDIUMCVSS 6.5≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.1+3 more2022-08-04
CVE-2022-34851 [MEDIUM] CWE-20 CVE-2022-34851: In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x be In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ Centralized Management all versions of 8.x, an authenticated attacker may cause iControl SOAP to become unavailable through undisclosed requests. Note: Software versions which have reached End of Te
nvd
CVE-2020-5938P3MEDIUMCVSS 6.5≥ 11.6.1, ≤ 11.6.5.2≥ 12.1.0, ≤ 12.1.5.2+2 more2020-10-29
CVE-2020-5938 [MEDIUM] CWE-326 CVE-2020-5938: On BIG-IP 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, when negotiating IPSec tunnels with On BIG-IP 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, when negotiating IPSec tunnels with configured, authenticated peers, the peer may negotiate a different key length than the BIG-IP configuration would otherwise allow.
nvd
CVE-2026-35062P3MEDIUMCVSS 6.5≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-35062 [MEDIUM] CWE-266 CVE-2026-35062: An authenticated iControl SOAP user may be able to obtain information of other accounts. Note: Sof An authenticated iControl SOAP user may be able to obtain information of other accounts. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2015-5058P4HIGHCVSS 7.8v11.5.1v11.5.3+1 more2015-08-24
CVE-2015-5058 [HIGH] CWE-399 CVE-2015-5058: Memory leak in the virtual server component in F5 Big-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Li Memory leak in the virtual server component in F5 Big-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and PEM 11.5.x before 11.5.1 HF10, 11.5.3 before HF1, and 11.6.0 before HF5, BIG-IQ Cloud, Device, and Security 4.4.0 through 4.5.0, and BIG-IQ ADC 4.5.0 allows remote attackers to cause a denial of service (memory consumption) via a large
nvd
CVE-2024-31156P3HIGHCVSS 8.0≥ 15.1.0, < 15.1.10.4≥ 16.1.0, < 16.1.4.3+1 more2024-05-08
CVE-2024-31156 [HIGH] CWE-79 CVE-2024-31156: A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Confi A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2018-5510P4HIGHCVSS 7.5v11.5.4v11.5.52018-04-13
CVE-2018-5510 [HIGH] CWE-20 CVE-2018-5510: On F5 BIG-IP 11.5.4 HF4-11.5.5, the Traffic Management Microkernel (TMM) may restart when processing On F5 BIG-IP 11.5.4 HF4-11.5.5, the Traffic Management Microkernel (TMM) may restart when processing a specific sequence of packets on IPv6 virtual servers.
nvd
CVE-2021-23023P4HIGHCVSS 7.8≥ 7.1.6, ≤ 7.1.9.9≥ 7.2.1, < 7.2.1.32021-06-10
CVE-2021-23023 [HIGH] CWE-427 CVE-2021-23023: On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, a DLL hijacking issue exists in On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, a DLL hijacking issue exists in cachecleaner.dll included in the BIG-IP Edge Client Windows Installer. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2020-5859P4HIGHCVSS 7.5≥ 15.0.0, ≤ 15.0.1.1v15.1.0.12020-03-27
CVE-2020-5859 [HIGH] CVE-2020-5859: On BIG-IP 15.1.0.1, specially formatted HTTP/3 messages may cause TMM to produce a core file. On BIG-IP 15.1.0.1, specially formatted HTTP/3 messages may cause TMM to produce a core file.
nvd
CVE-2019-6666P3HIGHCVSS 7.5≥ 13.1.0, ≤ 13.1.1.4≥ 14.0.0, ≤ 14.0.0.4+2 more2019-11-27
CVE-2019-6666 [HIGH] CVE-2019-6666: On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, and 13.1.0-13.1.1.4, the TMM process may On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, and 13.1.0-13.1.1.4, the TMM process may produce a core file when an upstream server or cache sends the BIG-IP an invalid age header value.
nvd
CVE-2019-6660P3HIGHCVSS 7.5≥ 13.1.0, < 13.1.3≥ 14.0.0, < 14.0.1.1+2 more2019-11-15
CVE-2019-6660 [HIGH] CWE-400 CVE-2019-6660: On BIG-IP 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.1, undisclosed HTTP requests may consume exc On BIG-IP 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.1, undisclosed HTTP requests may consume excessive amounts of systems resources which may lead to a denial of service.
nvd
CVE-2017-0301P4HIGHCVSS 7.6v11.5.0v11.5.1+9 more2017-12-21
CVE-2017-0301 [HIGH] CVE-2017-0301: In F5 BIG-IP APM software versions 11.5.0, 11.5.1, 11.5.2, 11.5.3, 11.5.4, 11.6.0, 11.6.1, 12.0.0, 1 In F5 BIG-IP APM software versions 11.5.0, 11.5.1, 11.5.2, 11.5.3, 11.5.4, 11.6.0, 11.6.1, 12.0.0, 12.1.0, 12.1.1 and 12.1.2 BIG-IP APM portal access requests do not return the intended resources in some cases. This may allow access to internal BIG-IP APM resources, however the application resources and backend servers are unaffected.
nvd
CVE-2019-6641P4MEDIUMCVSS 6.5≥ 12.1.2, ≤ 12.1.42019-07-03
CVE-2019-6641 [MEDIUM] CVE-2019-6641: On BIG-IP 12.1.0-12.1.4.1, undisclosed requests can cause iControl REST processes to crash. The atta On BIG-IP 12.1.0-12.1.4.1, undisclosed requests can cause iControl REST processes to crash. The attack can only come from an authenticated user; all roles are capable of performing the attack. Unauthenticated users cannot perform this attack.
nvd
CVE-2020-5912P4HIGHCVSS 7.1≥ 11.6.1, < 11.6.5.2≥ 12.1.0, < 12.1.5.2+5 more2020-08-26
CVE-2020-5912 [HIGH] CVE-2020-5912: In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5 In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the restjavad process's dump command does not follow current best coding practices and may overwrite arbitrary files.
nvd
CVE-2020-27724P4MEDIUMCVSS 6.5≥ 11.6.1, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+5 more2020-12-24
CVE-2020-27724 [MEDIUM] CWE-400 CVE-2020-27724: In BIG-IP APM versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.3, 13.1.0-13.1 In BIG-IP APM versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, on systems running more than one TMM instance, authenticated VPN users may consume excessive resources by sending specially-crafted malicious traffic over the tunnel.
nvd
CVE-2022-28859P4MEDIUMCVSS 6.5v14.1.0v14.1.2+11 more2022-05-05
CVE-2022-28859 [MEDIUM] CWE-532 CVE-2022-28859: On F5 BIG-IP 15.1.x versions prior to 15.1.5.1 and 14.1.x versions prior to 14.1.4.6, when installin On F5 BIG-IP 15.1.x versions prior to 15.1.5.1 and 14.1.x versions prior to 14.1.4.6, when installing Net HSM, the scripts (nethsm-safenet-install.sh and nethsm-thales-install.sh) expose the Net HSM partition password. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd