CVE-2022-1389
- EPSS 0.09%
- Published 05.05.2022 17:15:10
- Last modified 21.11.2024 06:40:37
On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP (fixed in 17.0.0), a cross-site request forgery (CSRF) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. This vulnerability allows an at...
CVE-2022-1468
- EPSS 0.19%
- Published 05.05.2022 17:15:10
- Last modified 21.11.2024 06:40:46
On all versions of 17.0.x, 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x on F5 BIG-IP, an authenticated iControl REST user with at least guest role privileges can cause processing delays to iControl REST requests via undisclosed requests. Note: ...
CVE-2022-23010
- EPSS 0.61%
- Published 25.01.2022 20:15:09
- Last modified 21.11.2024 06:47:47
On BIG-IP versions 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, when a FastL4 profile and an HTTP profile are configured on a virtual server, undisclosed requests can cause an inc...
CVE-2022-23011
- EPSS 0.68%
- Published 25.01.2022 20:15:09
- Last modified 21.11.2024 06:47:48
On certain hardware BIG-IP platforms, in version 15.1.x before 15.1.4 and 14.1.x before 14.1.3, virtual servers may stop responding while processing TCP traffic due to an issue in the SYN Cookie Protection feature. Note: Software versions which have ...
CVE-2022-23012
- EPSS 0.61%
- Published 25.01.2022 20:15:09
- Last modified 21.11.2024 06:47:48
On BIG-IP versions 15.1.x before 15.1.4.1 and 14.1.x before 14.1.4.5, when the HTTP/2 profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have ...
CVE-2022-23013
- EPSS 1.26%
- Published 25.01.2022 20:15:09
- Last modified 21.11.2024 06:47:48
On BIG-IP DNS & GTM version 16.x before 16.1.0, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, a DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configurati...
CVE-2022-23015
- EPSS 0.32%
- Published 25.01.2022 20:15:09
- Last modified 21.11.2024 06:47:48
On BIG-IP versions 16.x before 16.1.0, 15.1.x before 15.1.4.1, and 14.1.2.6-14.1.4.4, when a Client SSL profile is configured on a virtual server with Client Certificate Authentication set to request/require and Session Ticket enabled and configured,...
CVE-2022-23016
- EPSS 0.71%
- Published 25.01.2022 20:15:09
- Last modified 21.11.2024 06:47:48
On versions 16.1.x before 16.1.2 and 15.1.x before 15.1.4.1, when BIG-IP SSL Forward Proxy with TLS 1.3 is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions w...
CVE-2022-23017
- EPSS 0.71%
- Published 25.01.2022 20:15:09
- Last modified 21.11.2024 06:47:48
On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when a virtual server is configured with a DNS profile with the Rapid Response Mode setting enabled and is configured on a BIG-IP system...
CVE-2022-23019
- EPSS 0.61%
- Published 25.01.2022 20:15:09
- Last modified 21.11.2024 06:47:49
On BIG-IP version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x and 12.1.x, when a message routing type virtual server is configured with both Diameter Session and Router Profiles, undisclosed traffi...