cbcvebase.

F5 Big-Ip Access Policy Manager vulnerabilities

623 known vulnerabilities affecting f5/big-ip_access_policy_manager.

Total CVEs
623
CISA KEV
12
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL44HIGH336MEDIUM236LOW7

Vulnerabilities

Page 30 of 32
CVE-2018-5518P4MEDIUMCVSS 5.4≥ 12.0.0, ≤ 12.1.3≥ 13.0.0, ≤ 13.1.02018-05-02
CVE-2018-5518 [MEDIUM] CVE-2018-5518: On F5 BIG-IP 13.0.0-13.1.0.5 or 12.0.0-12.1.3.3, malicious root users with access to a VCMP guest ca On F5 BIG-IP 13.0.0-13.1.0.5 or 12.0.0-12.1.3.3, malicious root users with access to a VCMP guest can cause a disruption of service on adjacent VCMP guests running on the same host. Exploiting this vulnerability causes the vCMPd process on the adjacent VCMP guest to restart and produce a core file. This issue is only exploitable on a VCMP guest which is opera
nvd
CVE-2021-22981P4MEDIUMCVSS 4.8≥ 11.6.1, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+1 more2021-02-12
CVE-2021-22981 [MEDIUM] CVE-2021-22981: On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the ma On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiation that is mitigated by the Extended Master Secret (EMS) extension defined in RFC 7627. TLS connections that do not use EMS are vulnerable to man-in-the-middle attacks during renegotiation. Note: Software versions which have reached End o
nvd
CVE-2014-3959P4MEDIUMCVSS 4.3v11.2.1v11.5.12014-06-03
CVE-2014-3959 [MEDIUM] CWE-79 CVE-2014-3959: Cross-site scripting (XSS) vulnerability in list.jsp in the Configuration utility in F5 BIG-IP LTM, Cross-site scripting (XSS) vulnerability in list.jsp in the Configuration utility in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, GTM, and Link Controller 11.2.1 through 11.5.1, AAM 11.4.0 through 11.5.1 PEM 11.3.0 through 11.5.1, PSM 11.2.1 through 11.4.1, WebAccelerator and WOM 11.2.1 through 11.3.0, and Enterprise Manager 3.0.0 through 3.1.1 allows remot
nvd
CVE-2018-5516P4MEDIUMCVSS 4.7≥ 11.2.1, ≤ 11.6.3≥ 12.1.0, ≤ 12.1.2+1 more2018-05-02
CVE-2018-5516 [MEDIUM] CWE-732 CVE-2018-5516: On F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.2, or 11.2.1-11.6.3.1, Enterprise Manager 3.1.1, BIG-IQ Ce On F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.2, or 11.2.1-11.6.3.1, Enterprise Manager 3.1.1, BIG-IQ Centralized Management 5.0.0-5.4.0 or 4.6.0, BIG-IQ Cloud and Orchestration 1.0.0, or F5 iWorkflow 2.0.2-2.3.0, authenticated users granted TMOS Shell (tmsh) access can access objects on the file system which would normally be disallowed by tmsh restricti
nvd
CVE-2018-5525P4MEDIUMCVSS 4.3≥ 11.2.1, ≤ 11.5.5≥ 11.6.0, ≤ 11.6.3+2 more2018-06-01
CVE-2018-5525 [MEDIUM] CWE-200 CVE-2018-5525: A local file vulnerability exists in the F5 BIG-IP Configuration utility on versions 13.0.0, 12.1.0- A local file vulnerability exists in the F5 BIG-IP Configuration utility on versions 13.0.0, 12.1.0-12.1.2, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 that exposes files containing F5-provided data only and do not include any configuration data, proxied traffic, or other potentially sensitive customer data.
nvd
CVE-2014-9326P4MEDIUMCVSS 4.3v11.5.0v11.5.1+2 more2015-05-12
CVE-2014-9326 [MEDIUM] CVE-2014-9326: The automatic signature update functionality in the (1) Phone Home feature in F5 BIG-IP LTM, AAM, AF The automatic signature update functionality in the (1) Phone Home feature in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, GTM, and Link Controller 11.5.0 through 11.6.0, ASM 10.0.0 through 11.6.0, and PEM 11.3.0 through 11.6.0 and the (2) Call Home feature in ASM 10.0.0 through 11.6.0 and PEM 11.3.0 through 11.6.0 does not properly validate server SSL certificat
nvd
CVE-2022-27659P4MEDIUMCVSS 4.3v14.1.0v14.1.2+11 more2022-05-05
CVE-2022-27659 [MEDIUM] CWE-269 CVE-2022-27659: On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versio On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6, an authenticated attacker can modify or delete Dashboards created by other BIG-IP users in the Traffic Management User Interface (TMUI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2016-6249P4MEDIUMCVSS 5.3v11.5.0v11.5.1+6 more2017-02-20
CVE-2016-6249 [MEDIUM] CWE-200 CVE-2016-6249: F5 BIG-IP 12.0.0 and 11.5.0 - 11.6.1 REST requests which timeout during user account authentication F5 BIG-IP 12.0.0 and 11.5.0 - 11.6.1 REST requests which timeout during user account authentication may log sensitive attributes such as passwords in plaintext to /var/log/restjavad.0.log. It may allow local users to obtain sensitive information by reading these files.
nvd
CVE-2013-5976P4MEDIUMCVSS 4.3v10.1.0v10.2.4+3 more2013-10-01
CVE-2013-5976 [MEDIUM] CWE-79 CVE-2013-5976: Cross-site scripting (XSS) vulnerability in the access policy logout page (logout.inc) in F5 BIG-IP Cross-site scripting (XSS) vulnerability in the access policy logout page (logout.inc) in F5 BIG-IP APM 10.1.0 through 10.2.4 and 11.1.0 through 11.3.0 allows remote attackers to inject arbitrary web script or HTML via the LastMRH_Session cookie.
nvd
CVE-2013-5975P4MEDIUMCVSS 4.3v11.1.0v11.2.0+1 more2013-10-01
CVE-2013-5975 [MEDIUM] CWE-264 CVE-2013-5975: The access policy logon page (logon.inc) in F5 BIG-IP APM 11.1.0 through 11.2.1 allows remote attack The access policy logon page (logon.inc) in F5 BIG-IP APM 11.1.0 through 11.2.1 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
nvd
CVE-2019-6606P4MEDIUMCVSS 4.3≥ 11.5.1, ≤ 11.6.3.4≥ 12.1.0, ≤ 12.1.3.7+2 more2019-03-28
CVE-2019-6606 [MEDIUM] CWE-401 CVE-2019-6606: On BIG-IP 11.5.1-11.6.3.4, 12.1.0-12.1.3.7, 13.0.0-13.1.1.3, and 14.0.0-14.0.0.2, when processing ce On BIG-IP 11.5.1-11.6.3.4, 12.1.0-12.1.3.7, 13.0.0-13.1.1.3, and 14.0.0-14.0.0.2, when processing certain SNMP requests with a request-id of 0, the snmpd process may leak a small amount of memory.
nvd
CVE-2024-27202P4MEDIUMCVSS 4.7≥ 15.1.0, < 15.1.10.4≥ 16.1.0, < 16.1.4.3+1 more2024-05-08
CVE-2024-27202 [MEDIUM] CWE-79 CVE-2024-27202: A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Co A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2019-6598P4MEDIUMCVSS 4.3≥ 11.5.1, ≤ 11.5.8≥ 11.6.1, ≤ 11.6.3.2+3 more2019-03-13
CVE-2019-6598 [MEDIUM] CVE-2019-6598: In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.1-11.6.3.2, or 11.5.1-11.5.8 or En In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.1-11.6.3.2, or 11.5.1-11.5.8 or Enterprise Manager 3.1.1, malformed requests to the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, may lead to disruption of TMUI services. This attack requires an authenticated user with any role (other than the N
nvd
CVE-2020-5947P4MEDIUMCVSS 4.3≥ 15.0.0, < 15.1.2≥ 16.0.0, < 16.0.12020-11-19
CVE-2020-5947 [MEDIUM] CVE-2020-5947: In versions 16.0.0-16.0.0.1 and 15.1.0-15.1.1, on specific BIG-IP platforms, attackers may be able t In versions 16.0.0-16.0.0.1 and 15.1.0-15.1.1, on specific BIG-IP platforms, attackers may be able to obtain TCP sequence numbers from the BIG-IP system that can be reused in future connections with the same source and destination port and IP numbers. Only these platforms are affected: BIG-IP 2000 series (C112), BIG-IP 4000 series (C113), BIG-IP i2000 series
nvd
CVE-2023-38419P4MEDIUMCVSS 4.3≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.5+3 more2023-08-02
CVE-2023-38419 [MEDIUM] CWE-755 CVE-2023-38419: An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to ter An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending undisclosed requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2020-5898P4MEDIUMCVSS 5.5≥ 11.6.1, ≤ 11.6.5.1≥ 12.1.0, ≤ 12.1.5.1+3 more2020-05-12
CVE-2020-5898 [MEDIUM] CVE-2020-5898: In versions 7.1.5-7.1.9, BIG-IP Edge Client Windows Stonewall driver does not sanitize the pointer r In versions 7.1.5-7.1.9, BIG-IP Edge Client Windows Stonewall driver does not sanitize the pointer received from the userland. A local user on the Windows client system can send crafted DeviceIoControl requests to \\.\urvpndrv device causing the Windows kernel to crash.
nvd
CVE-2018-15310P4MEDIUMCVSS 4.3≥ 11.5.1, ≤ 11.5.7≥ 11.6.0, ≤ 11.6.3+1 more2018-09-13
CVE-2018-15310 [MEDIUM] CWE-200 CVE-2018-15310: A vulnerability in BIG-IP APM portal access 11.5.1-11.5.7, 11.6.0-11.6.3, and 12.1.0-12.1.3 disclose A vulnerability in BIG-IP APM portal access 11.5.1-11.5.7, 11.6.0-11.6.3, and 12.1.0-12.1.3 discloses the BIG-IP software version in rewritten pages.
nvd
CVE-2021-23002P4MEDIUMCVSS 4.5≥ 11.6.1, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+4 more2021-03-31
CVE-2021-23002 [MEDIUM] CVE-2021-23002: When using BIG-IP APM 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x b When using BIG-IP APM 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, or all 12.1.x and 11.6.x versions or Edge Client versions 7.2.1.x before 7.2.1.1, 7.1.9.x before 7.1.9.8, or 7.1.8.x before 7.1.8.5, the session ID is visible in the arguments of the f5vpn.exe command when VPN is launched from the browser on a
nvd
CVE-2019-6654P4MEDIUMCVSS 4.3≥ 11.5.1, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+2 more2019-09-25
CVE-2019-6654 [MEDIUM] CWE-20 CVE-2019-6654: On versions 14.0.0-14.1.2, 13.0.0-13.1.3, 12.1.0-12.1.5, and 11.5.1-11.6.5, the BIG-IP system fails On versions 14.0.0-14.1.2, 13.0.0-13.1.3, 12.1.0-12.1.5, and 11.5.1-11.6.5, the BIG-IP system fails to perform Martian Address Filtering (As defined in RFC 1812 section 5.3.7) on the control plane (management interface). This may allow attackers on an adjacent system to force BIG-IP into processing packets with spoofed source addresses.
nvd
CVE-2024-41723P4MEDIUMCVSS 4.3≥ 15.1.0, ≤ 15.1.1≥ 16.1.0, < 16.1.5+1 more2024-08-14
CVE-2024-41723 [MEDIUM] CWE-200 CVE-2024-41723: Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names. No Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
F5 Big-Ip Access Policy Manager vulnerabilities | cvebase