F5 Big-Ip Access Policy Manager vulnerabilities
623 known vulnerabilities affecting f5/big-ip_access_policy_manager.
Total CVEs
623
CISA KEV
12
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL44HIGH336MEDIUM236LOW7
Vulnerabilities
Page 23 of 32
CVE-2014-8730P4MEDIUMCVSS 4.3v10.1.0v10.2.0+12 more2014-12-10
CVE-2014-8730 [MEDIUM] CVE-2014-8730: The SSL profiles component in F5 BIG-IP LTM, APM, and ASM 10.0.0 through 10.2.4 and 11.0.0 through 1
The SSL profiles component in F5 BIG-IP LTM, APM, and ASM 10.0.0 through 10.2.4 and 11.0.0 through 11.5.1, AAM 11.4.0 through 11.5.1, AFM 11.3.0 through 11.5.1, Analytics 11.0.0 through 11.5.1, Edge Gateway, WebAccelerator, and WOM 10.1.0 through 10.2.4 and 11.0.0 through 11.3.0, PEM 11.3.0 through 11.6.0, and PSM 10.0.0 through 10.2.4 and 11.0.0 through 11.4
nvd
CVE-2022-27878P4MEDIUMCVSS 6.8v13.1.0v13.1.1+16 more2022-05-05
CVE-2022-27878 [MEDIUM] CWE-79 CVE-2022-27878: On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP, and F5 BIG-IP Gu
On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-
nvd
CVE-2018-15332P4HIGHCVSS 7.0≥ 11.5.1, ≤ 11.6.3≥ 12.1.0, ≤ 12.1.3+2 more2018-12-06
CVE-2018-15332 [HIGH] CWE-362 CVE-2018-15332: The svpn component of the F5 BIG-IP APM client prior to version 7.1.7.2 for Linux and macOS runs as
The svpn component of the F5 BIG-IP APM client prior to version 7.1.7.2 for Linux and macOS runs as a privileged process and can allow an unprivileged user to get ownership of files owned by root on the local client host in a race condition.
nvd
CVE-2016-9247P4MEDIUMCVSS 5.9v12.1.0v12.1.12017-01-10
CVE-2016-9247 [MEDIUM] CWE-20 CVE-2016-9247: Under certain conditions for BIG-IP systems using a virtual server with an associated FastL4 profile
Under certain conditions for BIG-IP systems using a virtual server with an associated FastL4 profile and TCP analytics profile, a specific sequence of packets may cause the Traffic Management Microkernel (TMM) to restart.
nvd
CVE-2016-3686P4MEDIUMCVSS 5.9v11.0.0v11.1.0+11 more2016-04-13
CVE-2016-3686 [MEDIUM] CWE-200 CVE-2016-3686: The Single Sign-On (SSO) feature in F5 BIG-IP APM 11.x before 11.6.0 HF6 and BIG-IP Edge Gateway 11.
The Single Sign-On (SSO) feature in F5 BIG-IP APM 11.x before 11.6.0 HF6 and BIG-IP Edge Gateway 11.0.0 through 11.3.0 might allow remote attackers to obtain sensitive SessionId information by leveraging access to the Location HTTP header in a redirect.
nvd
CVE-2016-9245P4MEDIUMCVSS 5.9v12.1.0v12.1.1+1 more2017-03-07
CVE-2016-9245 [MEDIUM] CWE-284 CVE-2016-9245: In F5 BIG-IP systems 12.1.0 - 12.1.2, malicious requests made to virtual servers with an HTTP profil
In F5 BIG-IP systems 12.1.0 - 12.1.2, malicious requests made to virtual servers with an HTTP profile can cause the TMM to restart. The issue is exposed with BIG-IP APM profiles, regardless of settings. The issue is also exposed with the non-default "Normalize URI" configuration options used in iRules and/or BIG-IP LTM policies. An attacker may be abl
nvd
CVE-2018-5500P4MEDIUMCVSS 5.9≥ 11.6.1, ≤ 11.6.2≥ 12.1.0, ≤ 12.1.3.1+1 more2018-03-01
CVE-2018-5500 [MEDIUM] CWE-400 CVE-2018-5500: On F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, or 11.6.1 - 11.6.2, every Multipath TCP (MCT
On F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, or 11.6.1 - 11.6.2, every Multipath TCP (MCTCP) connection established leaks a small amount of memory. Virtual server using TCP profile with Multipath TCP (MCTCP) feature enabled will be affected by this issue.
nvd
CVE-2021-22994P4MEDIUMCVSS 6.1≥ 11.6.1, < 11.6.5.3≥ 12.1.0, < 12.1.5.3+4 more2021-03-31
CVE-2021-22994 [MEDIUM] CVE-2021-22994: On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x befo
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete compromise of the BIG-IP system if the victim user is granted the admin role. This vulnera
nvd
CVE-2023-22418P4MEDIUMCVSS 6.1≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.3+3 more2023-02-01
CVE-2023-22418 [MEDIUM] CWE-601 CVE-2023-22418: On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.7, 14.1.x before 14.1
On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.7, 14.1.x before 14.1.5.3, and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy. This vulnerability allows an unauthenticated malicious attacker to build an open redirect URI. Note: Software versions
nvd
CVE-2022-28708P4MEDIUMCVSS 5.9v15.1.0v15.1.1+7 more2022-05-05
CVE-2022-28708 [MEDIUM] CWE-20 CVE-2022-28708: On F5 BIG-IP 16.1.x versions prior to 16.1.2.2 and 15.1.x versions prior to 15.1.5.1, when a BIG-IP
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2 and 15.1.x versions prior to 15.1.5.1, when a BIG-IP DNS resolver-enabled, HTTP-Explicit or SOCKS profile is configured on a virtual server, an undisclosed DNS response can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical Supp
nvd
CVE-2024-28889P4MEDIUMCVSS 5.9≥ 15.1.0, < 15.1.10.4≥ 16.1.0, < 16.1.4.3+1 more2024-05-08
CVE-2024-28889 [MEDIUM] CWE-825 CVE-2024-28889: When an SSL profile with alert timeout is configured with a non-default value on a virtual server
When an SSL profile with alert timeout is configured with a non-default value on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2016-7467P4MEDIUMCVSS 5.3v11.5.4v11.6.0+4 more2017-04-11
CVE-2016-7467 [MEDIUM] CWE-20 CVE-2016-7467: The TMM SSO plugin in F5 BIG-IP APM 12.0.0 - 12.1.1, 11.6.0 - 11.6.1 HF1, 11.5.4 - 11.5.4 HF2, when
The TMM SSO plugin in F5 BIG-IP APM 12.0.0 - 12.1.1, 11.6.0 - 11.6.1 HF1, 11.5.4 - 11.5.4 HF2, when configured as a SAML Identity Provider with a Service Provider (SP) connector, might allow traffic to be disrupted or failover initiated when a malformed, signed SAML authentication request from an authenticated user is sent via the SP connector.
nvd
CVE-2023-22372P4MEDIUMCVSS 5.9≥ 7.2.2, < 7.2.4.1≥ 13.1.0, ≤ 13.1.5+4 more2023-05-03
CVE-2023-22372 [MEDIUM] CWE-924 CVE-2023-22372: In the pre connection stage, an improper enforcement of message integrity vulnerability exists in B
In the pre connection stage, an improper enforcement of message integrity vulnerability exists in BIG-IP Edge Client for Windows and Mac OS. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2018-5524P4MEDIUMCVSS 5.3≥ 11.6.1, ≤ 11.6.3≥ 12.1.0, ≤ 12.1.3+1 more2018-06-01
CVE-2018-5524 [MEDIUM] CVE-2018-5524: Under certain conditions, on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, or 11.6.1 HF2-11.6.3.1, vir
Under certain conditions, on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, or 11.6.1 HF2-11.6.3.1, virtual servers configured with Client SSL or Server SSL profiles which make use of network hardware security module (HSM) functionality are exposed and impacted by this issue.
nvd
CVE-2017-6153P4MEDIUMCVSS 5.3≥ 11.5.1, ≤ 11.5.5≥ 11.6.1, ≤ 11.6.3+4 more2018-06-01
CVE-2017-6153 [MEDIUM] CWE-400 CVE-2017-6153: Features in F5 BIG-IP 13.0.0-13.1.0.3, 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 sy
Features in F5 BIG-IP 13.0.0-13.1.0.3, 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 system that utilizes inflate functionality directly, via an iRule, or via the inflate code from PEM module are subjected to a service disruption via a "Zip Bomb" attack.
nvd
CVE-2019-6647P4MEDIUMCVSS 5.3≥ 11.5.1, ≤ 11.6.4≥ 12.1.0, ≤ 12.1.4+3 more2019-09-04
CVE-2019-6647 [MEDIUM] CWE-401 CVE-2019-6647: On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, 12.1.0-12.1.4.1, 11.5.2-11.6.4, when proc
On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, 12.1.0-12.1.4.1, 11.5.2-11.6.4, when processing authentication attempts for control-plane users MCPD leaks a small amount of memory. Under rare conditions attackers with access to the management interface could eventually deplete memory on the system.
nvd
CVE-2022-23027P4MEDIUMCVSS 5.3≥ 12.1.5.3, ≤ 12.1.6≥ 13.1.3.6, ≤ 13.1.4+3 more2022-01-25
CVE-2022-23027 [MEDIUM] CWE-697 CVE-2022-23027: On BIG-IP versions 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, 13.1.x beginning in 13.1.3.6, 12.1.
On BIG-IP versions 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, 13.1.x beginning in 13.1.3.6, 12.1.5.3-12.1.6, and 11.6.5.2, when a FastL4 profile and an HTTP, FIX, and/or hash persistence profile are configured on the same virtual server, undisclosed requests can cause the virtual server to stop processing new client connections. Note: Software ve
nvd
CVE-2026-34019P4MEDIUMCVSS 5.3≥ 17.1.0, ≤ 17.1.2v17.5.0+1 more2026-05-13
CVE-2026-34019 [MEDIUM] CWE-410 CVE-2026-34019: When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols,
When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to stop processing BFD packets and cause the configured routing protocol to fail over. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2025-58424P4MEDIUMCVSS 5.3≥ 15.1.0, < 15.1.10.8≥ 16.1.0, < 16.1.6+1 more2025-10-15
CVE-2025-58424 [MEDIUM] CWE-340 CVE-2025-58424: On BIG-IP systems, undisclosed traffic can cause data corruption and unauthorized data modification
On BIG-IP systems, undisclosed traffic can cause data corruption and unauthorized data modification in protocols which do not have message integrity protection. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2018-5519P4MEDIUMCVSS 4.9≥ 11.2.1, ≤ 11.6.3≥ 12.1.0, ≤ 12.1.3+1 more2018-05-02
CVE-2018-5519 [MEDIUM] CVE-2018-5519: On F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.3, or 11.2.1-11.6.3.1, administrative users by way of un
On F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.3, or 11.2.1-11.6.3.1, administrative users by way of undisclosed methods can exploit the ssldump utility to write to arbitrary file paths. For users who do not have Advanced Shell access (for example, any user when licensed for Appliance Mode), this allows more permissive file access than intended.
nvd