F5

Big-ip Access Policy Manager

538 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.22%
  • Veröffentlicht 14.09.2021 13:15:11
  • Zuletzt bearbeitet 21.11.2024 05:51:13

On version 14.1.x before 14.1.4.4 and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy. This vulnerability allows an unauthenticated malicious user to build an open redirect URI....

  • EPSS 0.89%
  • Veröffentlicht 14.09.2021 13:15:10
  • Zuletzt bearbeitet 21.11.2024 05:51:13

On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x, when GPRS Tunneling Protocol (GTP) iRules commands or a GTP profile is configured on a virtual se...

  • EPSS 0.14%
  • Veröffentlicht 10.06.2021 16:15:08
  • Zuletzt bearbeitet 21.11.2024 05:51:10

On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, the BIG-IP Edge Client Windows Installer Service's temporary folder has weak file and folder permissions. Note: Software versions which have reached End of Technical Support (EoTS) ...

  • EPSS 0.09%
  • Veröffentlicht 10.06.2021 15:15:09
  • Zuletzt bearbeitet 21.11.2024 05:51:10

On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, a DLL hijacking issue exists in cachecleaner.dll included in the BIG-IP Edge Client Windows Installer. Note: Software versions which have reached End of Technical Support (EoTS) are...

  • EPSS 0.65%
  • Veröffentlicht 10.05.2021 15:15:07
  • Zuletzt bearbeitet 21.11.2024 05:51:08

On BIG-IP version 16.0.x before 16.0.1.1 and 15.1.x before 15.1.3, malformed HTTP/2 requests may cause an infinite loop which causes a Denial of Service for Data Plane traffic. TMM takes the configured HA action when the TMM process is aborted. There...

  • EPSS 0.19%
  • Veröffentlicht 10.05.2021 15:15:07
  • Zuletzt bearbeitet 21.11.2024 05:51:08

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, and 13.1.x before 13.1.4, lack of input validation for items used in the system support functionality may allow users granted either "Resource Administrator" or "A...

  • EPSS 0.09%
  • Veröffentlicht 10.05.2021 15:15:07
  • Zuletzt bearbeitet 21.11.2024 05:51:09

On BIG-IP 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.0.8 through 13.1.3.6, and all versions of 16.0.x, when running in Appliance Mode, an authenticated user assigned the 'Administrator' role may be able to bypass Appliance Mode restrictions u...

  • EPSS 0.26%
  • Veröffentlicht 10.05.2021 15:15:07
  • Zuletzt bearbeitet 21.11.2024 05:51:09

On BIG-IP APM versions 15.1.x before 15.1.3, 14.1.x before 14.1.4.1, 13.1.x before 13.1.4, and all versions of 16.0.x, 12.1.x, and 11.6.x, an attacker may be able to bypass APM's internal restrictions and retrieve static content that is hosted within...

  • EPSS 0.61%
  • Veröffentlicht 10.05.2021 14:15:07
  • Zuletzt bearbeitet 21.11.2024 05:51:08

On version 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and all versions of 16.0.x and 11.6.x., BIG-IP APM AD (Active Directory) authentication can be bypassed via a spoofed AS-REP (Kerberos Authentication S...

  • EPSS 0.65%
  • Veröffentlicht 10.05.2021 14:15:07
  • Zuletzt bearbeitet 21.11.2024 05:51:08

On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and 11.6.x before 11.6.5.3, when the BIG-IP system is buffering packet fragments for reassembly, the Traffic Management Microk...