cbcvebase.

F5 Big-Ip Access Policy Manager vulnerabilities

623 known vulnerabilities affecting f5/big-ip_access_policy_manager.

Total CVEs
623
CISA KEV
12
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL44HIGH336MEDIUM236LOW7

Vulnerabilities

Page 28 of 32
CVE-2018-5537P4MEDIUMCVSS 5.3≥ 11.2.1, ≤ 11.5.6≥ 11.6.0, ≤ 11.6.3.1+2 more2018-07-25
CVE-2018-5537 [MEDIUM] CWE-20 CVE-2018-5537: A remote attacker may be able to disrupt services on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11. A remote attacker may be able to disrupt services on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.2.1-11.5.6 if the TMM virtual server is configured with a HTML or a Rewrite profile. TMM may restart while processing some specially prepared HTML content from the back end.
nvd
CVE-2018-5532P4MEDIUMCVSS 5.3≥ 11.2.1, ≤ 11.5.6≥ 11.6.0, ≤ 11.6.3.1+2 more2018-07-19
CVE-2018-5532 [MEDIUM] CVE-2018-5532: On F5 BIG-IP 13.0.0, 12.1.0-12.1.2, 11.6.0-11.6.3.1, or 11.2.1-11.5.6 a domain name cached within th On F5 BIG-IP 13.0.0, 12.1.0-12.1.2, 11.6.0-11.6.3.1, or 11.2.1-11.5.6 a domain name cached within the DNS Cache of TMM may continue to be resolved by the cache even after the parent server revokes the record, if the DNS Cache is receiving a stream of requests for the cached name.
nvd
CVE-2019-6678P4MEDIUMCVSS 5.3≥ 13.1.0, < 13.1.3.2≥ 14.0.0, < 14.0.1.1+2 more2019-12-23
CVE-2019-6678 [MEDIUM] CVE-2019-6678: On BIG-IP versions 15.0.0-15.0.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, the TMM proce On BIG-IP versions 15.0.0-15.0.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, the TMM process may restart when the packet filter feature is enabled.
nvd
CVE-2019-6615P4MEDIUMCVSS 4.9≥ 11.5.2, < 11.5.9≥ 11.6.1, < 11.6.4+3 more2019-05-03
CVE-2019-6615 [MEDIUM] CVE-2019-6615: On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, Admin On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, Administrator and Resource Administrator roles might exploit TMSH access to bypass Appliance Mode restrictions on BIG-IP systems.
nvd
CVE-2019-6618P4MEDIUMCVSS 4.9≥ 11.5.2, ≤ 11.5.8≥ 11.6.1, ≤ 11.6.3.4+3 more2019-05-03
CVE-2019-6618 [MEDIUM] CVE-2019-6618: On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, users On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, users with the Resource Administrator role can modify sensitive portions of the filesystem if provided Advanced Shell Access, such as editing /etc/passwd. This allows modifications to user objects and is contrary to our definition for the Resource Administrator (RA)
nvd
CVE-2019-19150P4MEDIUMCVSS 4.9≥ 11.6.1, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+4 more2019-12-23
CVE-2019-19150 [MEDIUM] CWE-532 CVE-2019-19150: On versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5. On versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, the BIG-IP APM system logs the client-session-id when a per-session policy is attached to the virtual server with debug logging enabled.
nvd
CVE-2021-23046P4MEDIUMCVSS 4.9≥ 13.1.0, ≤ 13.1.4≥ 14.1.0, ≤ 14.1.4+2 more2021-09-14
CVE-2021-23046 [MEDIUM] CWE-532 CVE-2021-23046: On all versions of Guided Configuration before 8.0.0, when a configuration that contains secure prop On all versions of Guided Configuration before 8.0.0, when a configuration that contains secure properties is created and deployed from Access Guided Configuration (AGC), secure properties are logged in restnoded logs. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-22326P4MEDIUMCVSS 4.9≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.3+3 more2023-02-01
CVE-2023-22326 [MEDIUM] CWE-732 CVE-2023-22326: In BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x be In BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, and all versions of BIG-IQ 8.x and 7.1.x, incorrect permission assignment vulnerabilities exist in the iControl REST and TMOS shell (tmsh) dig command which may allow an authenticated attacker with resource a
nvd
CVE-2017-6134P4MEDIUMCVSS 6.5≥ 11.5.1, ≤ 11.6.1≥ 12.1.0, ≤ 12.1.2+1 more2017-12-21
CVE-2017-6134 [MEDIUM] CWE-20 CVE-2017-6134: In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and WebSafe software In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and WebSafe software version 13.0.0, 12.1.0 - 12.1.2 and 11.5.1 - 11.6.1, an undisclosed sequence of packets, sourced from an adjacent network may cause TMM to crash.
nvd
CVE-2018-15312P4MEDIUMCVSS 6.1≥ 12.1.0, ≤ 12.1.3.6≥ 13.0.0, ≤ 13.1.1.12018-10-19
CVE-2018-15312 [MEDIUM] CWE-79 CVE-2018-15312: On F5 BIG-IP 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, a reflected Cross-Site Scripting (XSS) vulnerabili On F5 BIG-IP 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, a reflected Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an authenticated user to execute JavaScript for the currently logged-in user.
nvd
CVE-2018-15315P4MEDIUMCVSS 6.1≥ 12.1.0, ≤ 12.1.3.6≥ 13.0.0, ≤ 13.1.1.12018-10-19
CVE-2018-15315 [MEDIUM] CWE-79 CVE-2018-15315: On F5 BIG-IP 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, there is a reflected Cross Site Scripting (XSS) vu On F5 BIG-IP 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, there is a reflected Cross Site Scripting (XSS) vulnerability in an undisclosed Configuration Utility page.
nvd
CVE-2023-27378P4MEDIUMCVSS 6.1≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.4+3 more2023-05-03
CVE-2023-27378 [MEDIUM] CWE-79 CVE-2023-27378: Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which allow an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-38138P4MEDIUMCVSS 6.1≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.5+3 more2023-08-02
CVE-2023-38138 [MEDIUM] CWE-79 CVE-2023-38138: A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Co A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2016-3687P4MEDIUMCVSS 5.3v11.2.1v11.4.0+7 more2016-06-16
CVE-2016-3687 [MEDIUM] CVE-2016-3687: Open redirect vulnerability in F5 BIG-IP APM 11.2.1, 11.4.x, 11.5.x, and 11.6.x before 11.6.0 HF6 an Open redirect vulnerability in F5 BIG-IP APM 11.2.1, 11.4.x, 11.5.x, and 11.6.x before 11.6.0 HF6 and Edge Gateway 11.2.1, when using multi-domain single sign-on (SSO), allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a base64-encoded URL in the SSO_ORIG_URI parameter.
nvd
CVE-2016-7474P4MEDIUMCVSS 5.5v11.2.1v11.4.0+11 more2017-03-27
CVE-2016-7474 [MEDIUM] CWE-200 CVE-2016-7474: In some cases the MCPD binary cache in F5 BIG-IP devices may allow a user with Advanced Shell access In some cases the MCPD binary cache in F5 BIG-IP devices may allow a user with Advanced Shell access, or privileges to generate a qkview, to temporarily obtain normally unrecoverable information.
nvd
CVE-2020-5908P4MEDIUMCVSS 5.5≥ 11.6.1, ≤ 11.6.5.2≥ 12.1.0, ≤ 12.1.52020-07-01
CVE-2020-5908 [MEDIUM] CWE-532 CVE-2020-5908: In versions bundled with BIG-IP APM 12.1.0-12.1.5 and 11.6.1-11.6.5.2, Edge Client for Linux exposes In versions bundled with BIG-IP APM 12.1.0-12.1.5 and 11.6.1-11.6.5.2, Edge Client for Linux exposes full session ID in the local log files.
nvd
CVE-2020-5923P4MEDIUMCVSS 5.4≥ 11.6.1, < 11.6.5.2≥ 12.1.0, < 12.1.5.2+3 more2020-08-26
CVE-2020-5923 [MEDIUM] CVE-2020-5923: In BIG-IP versions 15.0.0-15.1.0.4, 14.1.0-14.1.2.6, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11 In BIG-IP versions 15.0.0-15.1.0.4, 14.1.0-14.1.2.6, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1 and BIG-IQ versions 5.4.0-7.0.0, Self-IP port-lockdown bypass via IPv6 link-local addresses.
nvd
CVE-2017-0302P4MEDIUMCVSS 5.3v12.0.0v12.1.0+3 more2017-05-09
CVE-2017-0302 [MEDIUM] CWE-118 CVE-2017-0302: In F5 BIG-IP APM 12.0.0 through 12.1.2 and 13.0.0, an authenticated user with an established access In F5 BIG-IP APM 12.0.0 through 12.1.2 and 13.0.0, an authenticated user with an established access session to the BIG-IP APM system may be able to cause a traffic disruption if the length of the requested URL is less than 16 characters.
nvd
CVE-2023-24594P4MEDIUMCVSS 5.3v14.1.5v15.1.4.1+1 more2023-05-03
CVE-2023-24594 [MEDIUM] CWE-400 CVE-2023-24594: When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-38423P4MEDIUMCVSS 5.4≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.5+3 more2023-08-02
CVE-2023-38423 [MEDIUM] CWE-79 CVE-2023-38423: A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuratio A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd