F5 Big-Ip Access Policy Manager vulnerabilities
591 known vulnerabilities affecting f5/big-ip_access_policy_manager.
Total CVEs
591
CISA KEV
12
actively exploited
Public exploits
20
Exploited in wild
11
Severity breakdown
CRITICAL43HIGH321MEDIUM219LOW8
Vulnerabilities
Page 22 of 30
CVE-2019-9075HIGHCVSS 7.8v14.1.0v15.0.02019-02-24
CVE-2019-9075 [HIGH] CWE-787 CVE-2019-9075: An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is a heap-based buffer overflow in _bfd_archive_64_bit_slurp_armap in archive64.c.
nvd
CVE-2019-8331MEDIUMCVSS 6.1≥ 12.1.0, < 12.1.5.1≥ 13.0.0, < 13.1.3.4+2 more2019-02-20
CVE-2019-8331 [MEDIUM] CWE-79 CVE-2019-8331: In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-tem
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
nvd
CVE-2019-6974HIGHCVSS 8.1PoC≥ 13.0.0, ≤ 13.1.1≥ 14.0.0, ≤ 14.1.0+1 more2019-02-15
CVE-2019-6974 [HIGH] CWE-362 CVE-2019-6974: In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles referen
In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free.
nvd
CVE-2019-6589MEDIUMCVSS 6.1≥ 11.6.0, ≤ 11.6.3.2≥ 12.1.0, ≤ 12.1.3.7+2 more2019-02-14
CVE-2019-6589 [MEDIUM] CWE-79 CVE-2019-6589: On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.3, 12.1.0-12.1.3.7, and 11.6.0-11.6.3.2, a reflected Cross
On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.3, 12.1.0-12.1.3.7, and 11.6.0-11.6.3.2, a reflected Cross Site Scripting (XSS) vulnerability is present in an undisclosed page of the BIG-IP TMUI (Traffic Management User Interface) also known as the BIG-IP configuration utility.
nvd
CVE-2018-16890HIGHCVSS 7.5≥ 13.1.0, ≤ 13.1.3≥ 14.0.0, ≤ 14.1.2+1 more2019-02-06
CVE-2018-16890 [HIGH] CWE-125 CVE-2018-16890: libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The
libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incoming data correctly and is subject to an integer overflow vulnerability. Using that overflow, a malicious or broken NTLM server could tr
nvd
CVE-2019-6591MEDIUMCVSS 5.4≥ 12.1.0, ≤ 12.1.3≥ 13.0.0, ≤ 13.1.1.3+1 more2019-02-05
CVE-2019-6591 [MEDIUM] CWE-79 CVE-2019-6591: On BIG-IP APM 14.0.0 to 14.0.0.4, 13.0.0 to 13.1.1.3 and 12.1.0 to 12.1.3.7, a reflected cross-site
On BIG-IP APM 14.0.0 to 14.0.0.4, 13.0.0 to 13.1.1.3 and 12.1.0 to 12.1.3.7, a reflected cross-site scripting (XSS) vulnerability exists in the resource information page for authenticated users when a full webtop is configured on the BIG-IP APM system.
nvd
CVE-2018-15335MEDIUMCVSS 5.9≥ 13.0.0, ≤ 13.1.12018-12-28
CVE-2018-15335 [MEDIUM] CVE-2018-15335: When APM 13.0.0-13.1.x is deployed as an OAuth Resource Server, APM becomes a client application to
When APM 13.0.0-13.1.x is deployed as an OAuth Resource Server, APM becomes a client application to an external OAuth authorization server. In certain cases when communication between the BIG-IP APM and the OAuth authorization server is lost, APM may not display the intended message in the failure response
nvd
CVE-2018-15333MEDIUMCVSS 5.5≥ 11.2.1, ≤ 11.6.3≥ 12.1.0, ≤ 12.1.4+2 more2018-12-28
CVE-2018-15333 [MEDIUM] CWE-434 CVE-2018-15333: On versions 11.2.1. and greater, unrestricted Snapshot File Access allows BIG-IP system's user with
On versions 11.2.1. and greater, unrestricted Snapshot File Access allows BIG-IP system's user with any role, including Guest Role, to have access and download previously generated and available snapshot files on the BIG-IP configuration utility such as QKView and TCPDumps.
nvd
CVE-2018-15334MEDIUMCVSS 4.3≥ 11.5.1, ≤ 11.6.3≥ 12.1.0, ≤ 12.1.3+2 more2018-12-28
CVE-2018-15334 [MEDIUM] CWE-352 CVE-2018-15334: A cross-site request forgery (CSRF) vulnerability in the APM webtop 11.2.1 or greater may allow atta
A cross-site request forgery (CSRF) vulnerability in the APM webtop 11.2.1 or greater may allow attacker to force an APM webtop session to log out and require re-authentication.
nvd
CVE-2018-15330HIGHCVSS 7.5≥ 12.1.0, ≤ 12.1.3.7≥ 13.0.0, ≤ 13.1.1.1+1 more2018-12-20
CVE-2018-15330 [HIGH] CWE-20 CVE-2018-15330: On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.7, when a virtual server using the infl
On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.7, when a virtual server using the inflate functionality to process a gzip bomb as a payload, the BIG-IP system will experience a fatal error and may cause the Traffic Management Microkernel (TMM) to produce a core file.
nvd
CVE-2018-15329HIGHCVSS 7.2≥ 12.1.0, ≤ 12.1.3.7≥ 13.0.0, ≤ 13.1.1.1+1 more2018-12-20
CVE-2018-15329 [HIGH] CWE-862 CVE-2018-15329: On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.7, or Enterprise Manager 3.1.1, when au
On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.7, or Enterprise Manager 3.1.1, when authenticated administrative users run commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.
nvd
CVE-2018-15328HIGHCVSS 7.5≥ 11.2.1, ≤ 11.6.3≥ 12.1.0, ≤ 12.1.3+2 more2018-12-12
CVE-2018-15328 [HIGH] CWE-200 CVE-2018-15328: On BIG-IP 14.0.x, 13.x, 12.x, and 11.x, Enterprise Manager 3.1.1, BIG-IQ 6.x, 5.x, and 4.x, and iWor
On BIG-IP 14.0.x, 13.x, 12.x, and 11.x, Enterprise Manager 3.1.1, BIG-IQ 6.x, 5.x, and 4.x, and iWorkflow 2.x, the passphrases for SNMPv3 users and trap destinations that are used for authentication and privacy are not handled by the BIG-IP system Secure Vault feature; they are written in the clear to the various configuration files.
nvd
CVE-2018-15332HIGHCVSS 7.0≥ 11.5.1, ≤ 11.6.3≥ 12.1.0, ≤ 12.1.3+2 more2018-12-06
CVE-2018-15332 [HIGH] CWE-362 CVE-2018-15332: The svpn component of the F5 BIG-IP APM client prior to version 7.1.7.2 for Linux and macOS runs as
The svpn component of the F5 BIG-IP APM client prior to version 7.1.7.2 for Linux and macOS runs as a privileged process and can allow an unprivileged user to get ownership of files owned by root on the local client host in a race condition.
nvd
CVE-2018-15319HIGHCVSS 7.5≥ 12.1.0, ≤ 12.1.3.6≥ 13.0.0, ≤ 13.1.1.1+1 more2018-10-31
CVE-2018-15319 [HIGH] CWE-20 CVE-2018-15319: On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.6, malicious requests made to virtual s
On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.6, malicious requests made to virtual servers with an HTTP profile can cause the TMM to restart. The issue is exposed with the non-default "normalize URI" configuration options used in iRules and/or BIG-IP LTM policies.
nvd
CVE-2018-15327HIGHCVSS 7.2≥ 13.0.0, ≤ 13.1.1.1≥ 14.0.0, ≤ 14.0.0.22018-10-31
CVE-2018-15327 [HIGH] CWE-862 CVE-2018-15327: In BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1 or Enterprise Manager 3.1.1, when authenticated adminis
In BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1 or Enterprise Manager 3.1.1, when authenticated administrative users run commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.
nvd
CVE-2018-15317HIGHCVSS 7.5≥ 11.2.1, ≤ 11.5.6≥ 11.6.0, ≤ 11.6.3.2+3 more2018-10-31
CVE-2018-15317 [HIGH] CVE-2018-15317: In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, and 11.2.1-11.6.3.2, an attacker sendin
In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, and 11.2.1-11.6.3.2, an attacker sending specially crafted SSL records to a SSL Virtual Server will cause corruption in the SSL data structures leading to intermittent decrypt BAD_RECORD_MAC errors. Clients will be unable to access the application load balanced by a virtual server with an SSL profil
nvd
CVE-2018-15320HIGHCVSS 7.5≥ 13.0.0, ≤ 13.1.1.1≥ 14.0.0, ≤ 14.0.0.22018-10-31
CVE-2018-15320 [HIGH] CVE-2018-15320: On BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, undisclosed traffic patterns may lead to denial of ser
On BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, undisclosed traffic patterns may lead to denial of service conditions for the BIG-IP system. The configuration which exposes this condition is the BIG-IP self IP address which is part of a VLAN group and has the Port Lockdown setting configured with anything other than "allow-all".
nvd
CVE-2018-15318HIGHCVSS 7.5≥ 12.1.3.4, ≤ 12.1.3.6≥ 13.0.0, ≤ 13.1.1.1+1 more2018-10-31
CVE-2018-15318 [HIGH] CWE-20 CVE-2018-15318: In BIG-IP 14.0.0-14.0.0.2, 13.1.0.4-13.1.1.1, or 12.1.3.4-12.1.3.6, If an MPTCP connection receives
In BIG-IP 14.0.0-14.0.0.2, 13.1.0.4-13.1.1.1, or 12.1.3.4-12.1.3.6, If an MPTCP connection receives an abort signal while the initial flow is not the primary flow, the initial flow will remain after the closing procedure is complete. TMM may restart and produce a core file as a result of this condition.
nvd
CVE-2018-15326HIGHCVSS 7.5≥ 11.6.0, ≤ 11.6.3.2≥ 12.1.0, ≤ 12.1.3.5+2 more2018-10-31
CVE-2018-15326 [HIGH] CWE-295 CVE-2018-15326: In some situations on BIG-IP APM 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, or 11.6.0-11.6.3
In some situations on BIG-IP APM 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, or 11.6.0-11.6.3.2, the CRLDP Auth access policy agent may treat revoked certificates as valid when the BIG-IP APM system fails to download a new Certificate Revocation List.
nvd
CVE-2018-15322MEDIUMCVSS 6.5≥ 11.2.1, ≤ 11.5.6≥ 11.6.0, ≤ 11.6.3.2+3 more2018-10-31
CVE-2018-15322 [MEDIUM] CVE-2018-15322: On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.2.1-11.5.6, BIG-
On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.2.1-11.5.6, BIG-IQ Centralized Management 6.0.0-6.0.1, 5.0.0-5.4.0 or 4.6.0, BIG-IQ Cloud and Orchestration 1.0.0, iWorkflow 2.0.1-2.3.0, or Enterprise Manager 3.1.1 a BIG-IP user granted with tmsh access may cause the BIG-IP system to experience denial-of-service (DoS) when
nvd