F5

Big-ip Access Policy Manager

625 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.99%
  • Veröffentlicht 14.09.2021 15:15:07
  • Zuletzt bearbeitet 21.11.2024 05:51:12

On BIG-IP, on all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to access arbitrary files. Note: S...

  • EPSS 0.77%
  • Veröffentlicht 14.09.2021 15:15:07
  • Zuletzt bearbeitet 21.11.2024 05:51:12

On all versions of Guided Configuration before 8.0.0, when a configuration that contains secure properties is created and deployed from Access Guided Configuration (AGC), secure properties are logged in restnoded logs. Note: Software versions which h...

  • EPSS 0.58%
  • Veröffentlicht 14.09.2021 14:15:10
  • Zuletzt bearbeitet 21.11.2024 05:51:12

On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a DOM based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration...

  • EPSS 0.6%
  • Veröffentlicht 14.09.2021 14:15:10
  • Zuletzt bearbeitet 21.11.2024 05:51:13

On version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, and all versions of 13.1.x, 12.1.x and 11.6.x, when BIG-IP APM performs Online Certificate Status Protocol (OCSP) verification of a certificate that contains Authority Inf...

  • EPSS 0.96%
  • Veröffentlicht 14.09.2021 13:15:11
  • Zuletzt bearbeitet 21.11.2024 05:51:13

On BIG-IP version 16.0.x before 16.0.1.2 and 15.1.x before 15.1.3, when the iRules RESOLVER::summarize command is used on a virtual server, undisclosed requests can cause an increase in Traffic Management Microkernel (TMM) memory utilization resultin...

  • EPSS 0.96%
  • Veröffentlicht 14.09.2021 13:15:11
  • Zuletzt bearbeitet 21.11.2024 05:51:13

On BIG-IP versions 15.1.0.4 through 15.1.3, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP on Amazon Web Services (AWS) systems, undisclosed requests can cause the Traffic Management Microkernel (T...

  • EPSS 0.58%
  • Veröffentlicht 14.09.2021 13:15:11
  • Zuletzt bearbeitet 21.11.2024 05:51:13

On version 14.1.x before 14.1.4.4 and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy. This vulnerability allows an unauthenticated malicious user to build an open redirect URI....

  • EPSS 0.96%
  • Veröffentlicht 14.09.2021 13:15:10
  • Zuletzt bearbeitet 21.11.2024 05:51:13

On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x, when GPRS Tunneling Protocol (GTP) iRules commands or a GTP profile is configured on a virtual se...

  • EPSS 0.23%
  • Veröffentlicht 10.06.2021 16:15:08
  • Zuletzt bearbeitet 21.11.2024 05:51:10

On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, the BIG-IP Edge Client Windows Installer Service's temporary folder has weak file and folder permissions. Note: Software versions which have reached End of Technical Support (EoTS) ...

  • EPSS 0.3%
  • Veröffentlicht 10.06.2021 15:15:09
  • Zuletzt bearbeitet 21.11.2024 05:51:10

On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, a DLL hijacking issue exists in cachecleaner.dll included in the BIG-IP Edge Client Windows Installer. Note: Software versions which have reached End of Technical Support (EoTS) are...