cbcvebase.

F5 Big-Ip Application Acceleration Manager vulnerabilities

518 known vulnerabilities affecting f5/big-ip_application_acceleration_manager.

Total CVEs
518
CISA KEV
11
actively exploited
Public exploits
19
Exploited in wild
15
Severity breakdown
CRITICAL37HIGH290MEDIUM187LOW4

Vulnerabilities

Page 23 of 26
CVE-2018-15321P4MEDIUMCVSS 4.9≥ 11.2.1, ≤ 11.5.6≥ 11.6.0, ≤ 11.6.3.2+3 more2018-10-31
CVE-2018-15321 [MEDIUM] CWE-269 CVE-2018-15321: When BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.2.1-11.5.6, BI When BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.2.1-11.5.6, BIG-IQ Centralized Management 5.0.0-5.4.0 or 4.6.0, BIG-IQ Cloud and Orchestration 1.0.0, iWorkflow 2.1.0-2.3.0, or Enterprise Manager 3.1.1 is licensed for Appliance Mode, Admin and Resource administrator roles can by-pass BIG-IP Appliance Mode restric
nvd
CVE-2020-27727P4MEDIUMCVSS 4.9≥ 13.1.0, < 13.1.3.5≥ 14.1.0, < 14.1.3.1+2 more2020-12-24
CVE-2020-27727 [MEDIUM] CWE-20 CVE-2020-27727: On BIG-IP version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, when an auth On BIG-IP version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, when an authenticated administrative user installs RPMs using the iAppsLX REST installer, the BIG-IP system does not sufficiently validate user input, allowing the user read access to the filesystem.
nvd
CVE-2022-26340P4MEDIUMCVSS 4.9v11.6.1v11.6.2+29 more2022-05-05
CVE-2022-26340 [MEDIUM] CWE-732 CVE-2022-26340: On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions p On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, and F5 BIG-IQ Centralized Management all versions of 8.x and 7.x, an authenticated, high-privileged attacker with no bash access may be able to access Certificat
nvd
CVE-2026-41954P4MEDIUMCVSS 4.9≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-41954 [MEDIUM] CWE-200 CVE-2026-41954: Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2022-29474P4MEDIUMCVSS 4.3v11.6.1v11.6.2+29 more2022-05-05
CVE-2022-29474 [MEDIUM] CWE-22 CVE-2022-29474: On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions p On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, a directory traversal vulnerability exists in iControl SOAP that allows an authenticated attacker with at least guest role privileges to read wsdl files in the BI
nvd
CVE-2018-5521P4MEDIUMCVSS 6.1≥ 11.5.1, ≤ 11.5.5≥ 11.6.1, ≤ 11.6.3+2 more2018-06-01
CVE-2018-5521 [MEDIUM] CWE-79 CVE-2018-5521: On F5 BIG-IP 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, carefully crafted URLs can On F5 BIG-IP 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, carefully crafted URLs can be used to reflect arbitrary content into GeoIP lookup responses, potentially exposing clients to XSS.
nvd
CVE-2019-6625P4MEDIUMCVSS 6.1≥ 11.5.1, ≤ 11.6.3≥ 12.1.0, < 12.1.4.1+3 more2019-07-03
CVE-2019-6625 [MEDIUM] CWE-79 CVE-2019-6625: On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a ref On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traffic Management User Interface (TMUI) also known as the BIG-IP Configuration utility.
nvd
CVE-2019-6589P4MEDIUMCVSS 6.1≥ 11.6.0, ≤ 11.6.3.2≥ 12.1.0, ≤ 12.1.3.7+2 more2019-02-14
CVE-2019-6589 [MEDIUM] CWE-79 CVE-2019-6589: On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.3, 12.1.0-12.1.3.7, and 11.6.0-11.6.3.2, a reflected Cross On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.3, 12.1.0-12.1.3.7, and 11.6.0-11.6.3.2, a reflected Cross Site Scripting (XSS) vulnerability is present in an undisclosed page of the BIG-IP TMUI (Traffic Management User Interface) also known as the BIG-IP configuration utility.
nvd
CVE-2020-27719P4MEDIUMCVSS 6.1≥ 14.1.0, < 14.1.3.1≥ 15.0.0, < 15.1.1+1 more2020-12-24
CVE-2020-27719 [MEDIUM] CWE-79 CVE-2020-27719: On BIG-IP 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.3, a cross-site scripting (XSS) vulnerab On BIG-IP 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.3, a cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility.
nvd
CVE-2019-6657P4MEDIUMCVSS 6.1≥ 11.5.2, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+1 more2019-11-01
CVE-2019-6657 [MEDIUM] CWE-79 CVE-2019-6657: On BIG-IP 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, a reflected cross-site scripting (XSS On BIG-IP 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traffic Management User Interface (TMUI), also known as the BIG-IP Configuration utility.
nvd
CVE-2024-33604P4MEDIUMCVSS 6.1≥ 15.1.0, < 15.1.10.4≥ 16.1.0, < 16.1.4.3+1 more2024-05-08
CVE-2024-33604 [MEDIUM] CWE-79 CVE-2024-33604: A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Config A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2016-7469P4MEDIUMCVSS 5.4v11.4.0v11.4.1+11 more2017-06-09
CVE-2016-7469 [MEDIUM] CWE-79 CVE-2016-7469: A stored cross-site scripting (XSS) vulnerability in the Configuration utility device name change pa A stored cross-site scripting (XSS) vulnerability in the Configuration utility device name change page in BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, PSM, WebAccelerator, WOM and WebSafe version 12.0.0 - 12.1.2, 11.4.0 - 11.6.1, and 11.2.1 allows an authenticated user to inject arbitrary web script or HTML.
nvd
CVE-2018-5537P4MEDIUMCVSS 5.3≥ 11.2.1, ≤ 11.5.6≥ 11.6.0, ≤ 11.6.3.1+2 more2018-07-25
CVE-2018-5537 [MEDIUM] CWE-20 CVE-2018-5537: A remote attacker may be able to disrupt services on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11. A remote attacker may be able to disrupt services on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.2.1-11.5.6 if the TMM virtual server is configured with a HTML or a Rewrite profile. TMM may restart while processing some specially prepared HTML content from the back end.
nvd
CVE-2018-5532P4MEDIUMCVSS 5.3≥ 11.2.1, ≤ 11.5.6≥ 11.6.0, ≤ 11.6.3.1+2 more2018-07-19
CVE-2018-5532 [MEDIUM] CVE-2018-5532: On F5 BIG-IP 13.0.0, 12.1.0-12.1.2, 11.6.0-11.6.3.1, or 11.2.1-11.5.6 a domain name cached within th On F5 BIG-IP 13.0.0, 12.1.0-12.1.2, 11.6.0-11.6.3.1, or 11.2.1-11.5.6 a domain name cached within the DNS Cache of TMM may continue to be resolved by the cache even after the parent server revokes the record, if the DNS Cache is receiving a stream of requests for the cached name.
nvd
CVE-2019-6678P4MEDIUMCVSS 5.3≥ 13.1.0, < 13.1.3.2≥ 14.0.0, < 14.0.1.1+2 more2019-12-23
CVE-2019-6678 [MEDIUM] CVE-2019-6678: On BIG-IP versions 15.0.0-15.0.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, the TMM proce On BIG-IP versions 15.0.0-15.0.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, the TMM process may restart when the packet filter feature is enabled.
nvd
CVE-2019-6615P4MEDIUMCVSS 4.9≥ 11.5.2, < 11.5.9≥ 11.6.1, < 11.6.4+3 more2019-05-03
CVE-2019-6615 [MEDIUM] CVE-2019-6615: On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, Admin On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, Administrator and Resource Administrator roles might exploit TMSH access to bypass Appliance Mode restrictions on BIG-IP systems.
nvd
CVE-2019-6618P4MEDIUMCVSS 4.9≥ 11.5.2, ≤ 11.5.8≥ 11.6.1, ≤ 11.6.3.4+3 more2019-05-03
CVE-2019-6618 [MEDIUM] CVE-2019-6618: On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, users On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, users with the Resource Administrator role can modify sensitive portions of the filesystem if provided Advanced Shell Access, such as editing /etc/passwd. This allows modifications to user objects and is contrary to our definition for the Resource Administrator (RA)
nvd
CVE-2023-22326P4MEDIUMCVSS 4.9≥ 13.1.0, ≤ 13.1.5≥ 15.1.0, < 15.1.8.1+2 more2023-02-01
CVE-2023-22326 [MEDIUM] CWE-732 CVE-2023-22326: In BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x be In BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, and all versions of BIG-IQ 8.x and 7.1.x, incorrect permission assignment vulnerabilities exist in the iControl REST and TMOS shell (tmsh) dig command which may allow an authenticated attacker with resource a
nvd
CVE-2017-6134P4MEDIUMCVSS 6.5≥ 11.5.1, ≤ 11.6.1≥ 12.1.0, ≤ 12.1.2+1 more2017-12-21
CVE-2017-6134 [MEDIUM] CWE-20 CVE-2017-6134: In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and WebSafe software In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and WebSafe software version 13.0.0, 12.1.0 - 12.1.2 and 11.5.1 - 11.6.1, an undisclosed sequence of packets, sourced from an adjacent network may cause TMM to crash.
nvd
CVE-2018-15312P4MEDIUMCVSS 6.1≥ 12.1.0, ≤ 12.1.3.6≥ 13.0.0, ≤ 13.1.1.12018-10-19
CVE-2018-15312 [MEDIUM] CWE-79 CVE-2018-15312: On F5 BIG-IP 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, a reflected Cross-Site Scripting (XSS) vulnerabili On F5 BIG-IP 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, a reflected Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an authenticated user to execute JavaScript for the currently logged-in user.
nvd