F5 Big-Ip Access Policy Manager vulnerabilities

591 known vulnerabilities affecting f5/big-ip_access_policy_manager.

Total CVEs
591
CISA KEV
12
actively exploited
Public exploits
19
Exploited in wild
11
Severity breakdown
CRITICAL43HIGH321MEDIUM219LOW8

Vulnerabilities

Page 5 of 30
CVE-2023-45219MEDIUMCVSS 4.4≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+2 more2023-10-10
CVE-2023-45219 [MEDIUM] CWE-200 CVE-2023-45219: Exposure of Sensitive Information vulnerability exist in an undisclosed BIG-IP TMOS shell (tmsh) co Exposure of Sensitive Information vulnerability exist in an undisclosed BIG-IP TMOS shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-43485MEDIUMCVSS 5.5≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+2 more2023-10-10
CVE-2023-43485 [MEDIUM] CWE-532 CVE-2023-43485: When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in p When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audit log. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-41964MEDIUMCVSS 6.5≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+2 more2023-10-10
CVE-2023-41964 [MEDIUM] CWE-312 CVE-2023-41964: The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) va The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-39447MEDIUMCVSS 4.4≥ 15.1.0, < 15.1.8≥ 16.1.0, < 16.1.4+1 more2023-10-10
CVE-2023-39447 [MEDIUM] CWE-532 CVE-2023-39447: When BIG-IP APM Guided Configurations are configured, undisclosed sensitive information may be logg When BIG-IP APM Guided Configurations are configured, undisclosed sensitive information may be logged in restnoded log. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-43125HIGHCVSS 8.2≥ 14.1.5.2, ≤ 14.1.5.6≥ 15.1.8, ≤ 15.1.10+3 more2023-09-27
CVE-2023-43125 [HIGH] CWE-319 CVE-2023-43125: BIG-IP APM clients may send IP traffic outside of the VPN tunnel.  Note: Software versions which ha BIG-IP APM clients may send IP traffic outside of the VPN tunnel. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2023-43124HIGHCVSS 7.1≥ 14.1.5.2, ≤ 14.1.5.6≥ 15.1.8, ≤ 15.1.10+3 more2023-09-27
CVE-2023-43124 [HIGH] CWE-319 CVE-2023-43124: BIG-IP APM clients may send IP traffic outside of the VPN tunnel.  Note: Software versions which ha BIG-IP APM clients may send IP traffic outside of the VPN tunnel. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2023-38418HIGHCVSS 7.8≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+3 more2023-08-02
CVE-2023-38418 [HIGH] CWE-347 CVE-2023-38418: The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges d The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-3470MEDIUMCVSS 6.1≥ 13.1.0, < 13.1.4≥ 14.1.0, < 14.1.4+1 more2023-08-02
CVE-2023-3470 [MEDIUM] CWE-1391 CVE-2023-3470: Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password fo Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User account. The predictable nature of the password allows an authenticated user with TMSH access to the BIG-IP system, or anyone with physical access to the FIPS HSM, the information required to generate the correct password. On vCMP syst
nvd
CVE-2023-38138MEDIUMCVSS 6.1≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.5+3 more2023-08-02
CVE-2023-38138 [MEDIUM] CWE-79 CVE-2023-38138: A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Co A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-36858MEDIUMCVSS 5.5≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+3 more2023-08-02
CVE-2023-36858 [MEDIUM] CWE-345 CVE-2023-36858: An insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and mac An insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and macOS that may allow an attacker to modify its configured server list. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-38419MEDIUMCVSS 4.3≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.5+3 more2023-08-02
CVE-2023-38419 [MEDIUM] CWE-755 CVE-2023-38419: An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to ter An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending undisclosed requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-38423MEDIUMCVSS 5.4≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.5+3 more2023-08-02
CVE-2023-38423 [MEDIUM] CWE-79 CVE-2023-38423: A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuratio A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-29163HIGHCVSS 7.5≥ 14.1.0, < 14.1.5.4≥ 15.1.0, < 15.1.8.2+2 more2023-05-03
CVE-2023-29163 [HIGH] CWE-401 CVE-2023-29163: When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual serve When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-24594MEDIUMCVSS 5.3v14.1.5v15.1.4.1+1 more2023-05-03
CVE-2023-24594 [MEDIUM] CWE-400 CVE-2023-24594: When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-24461MEDIUMCVSS 5.9≥ 7.2.2, < 7.2.4.1≥ 13.1.0, ≤ 13.1.5+4 more2023-05-03
CVE-2023-24461 [MEDIUM] CWE-295 CVE-2023-24461: An improper certificate validation vulnerability exists in the BIG-IP Edge Client for Windows and m An improper certificate validation vulnerability exists in the BIG-IP Edge Client for Windows and macOS and may allow an attacker to impersonate a BIG-IP APM system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-28406MEDIUMCVSS 4.3≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.4+3 more2023-05-03
CVE-2023-28406 [MEDIUM] CWE-22 CVE-2023-28406: A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utilit A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which may allow an authenticated attacker to read files with .xml extension. Access to restricted information is limited and the attacker does not control what information is obtained. Note: Software versions which have reached End of Technical Sup
nvd
CVE-2023-22372MEDIUMCVSS 5.9≥ 7.2.2, < 7.2.4.1≥ 13.1.0, ≤ 13.1.5+4 more2023-05-03
CVE-2023-22372 [MEDIUM] CWE-924 CVE-2023-22372: In the pre connection stage, an improper enforcement of message integrity vulnerability exists in B In the pre connection stage, an improper enforcement of message integrity vulnerability exists in BIG-IP Edge Client for Windows and Mac OS. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-27378MEDIUMCVSS 6.1≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.4+3 more2023-05-03
CVE-2023-27378 [MEDIUM] CWE-79 CVE-2023-27378: Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which allow an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-22422HIGHCVSS 7.5≥ 16.1.0, < 16.1.3.3≥ 17.0.0, < 17.0.0.22023-02-01
CVE-2023-22422 [HIGH] CWE-120 CVE-2023-22422: On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, when a HTTP profile with the n On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, when a HTTP profile with the non-default Enforcement options of Enforce HTTP Compliance and Unknown Methods: Reject are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached En
nvd
CVE-2023-22358HIGHCVSS 7.8≥ 7.2.2, < 7.2.3.1≥ 13.1.0, ≤ 13.1.5+4 more2023-02-01
CVE-2023-22358 [HIGH] CWE-427 CVE-2023-22358: In versions beginning with 7.2.2 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG- In versions beginning with 7.2.2 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client Windows Installer. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd