F5

Big-ip Access Policy Manager Client

18 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.09%
  • Published 30.04.2020 22:15:12
  • Last modified 21.11.2024 05:34:46

In versions 7.1.5-7.1.8, the BIG-IP Edge Client components in BIG-IP APM, Edge Gateway, and FirePass legacy allow attackers to obtain the full session ID from process memory.

  • EPSS 0.13%
  • Published 30.04.2020 21:15:17
  • Last modified 21.11.2024 05:34:46

In versions 7.1.5-7.1.8, when a user connects to a VPN using BIG-IP Edge Client over an unsecure network, BIG-IP Edge Client responds to authentication requests over HTTP while sending probes for captive portal detection.

  • EPSS 0.15%
  • Published 06.02.2020 16:15:12
  • Last modified 21.11.2024 05:34:42

When the Windows Logon Integration feature is configured for all versions of BIG-IP Edge Client for Windows, unauthorized users who have physical access to an authorized user's machine can get shell access under unprivileged user.

  • EPSS 0.54%
  • Published 25.09.2019 20:15:11
  • Last modified 21.11.2024 04:46:53

BIG-IP APM Edge Client before version 7.1.8 (7180.2019.508.705) logs the full apm session ID in the log files. Vulnerable versions of the client are bundled with BIG-IP APM versions 15.0.0-15.0.1, 14,1.0-14.1.0.6, 14.0.0-14.0.0.4, 13.0.0-13.1.1.5, 12...

  • EPSS 0.12%
  • Published 06.12.2018 13:29:00
  • Last modified 21.11.2024 03:50:35

The svpn component of the F5 BIG-IP APM client prior to version 7.1.7.2 for Linux and macOS runs as a privileged process and can allow an unprivileged user to get ownership of files owned by root on the local client host in a race condition.

  • EPSS 0.14%
  • Published 19.10.2018 13:29:00
  • Last modified 21.11.2024 03:50:32

In F5 BIG-IP APM 13.0.0-13.1.1.1, APM Client 7.1.5-7.1.6, and/or Edge Client 7101-7160, the BIG-IP APM Edge Client component loads the policy library with user permission and bypassing the endpoint checks.

Exploit
  • EPSS 0.13%
  • Published 17.08.2018 12:29:00
  • Last modified 21.11.2024 04:09:02

The svpn and policyserver components of the F5 BIG-IP APM client prior to version 7.1.7.1 for Linux and macOS runs as a privileged process and can allow an unprivileged user to get ownership of files owned by root on the local client host. A maliciou...

  • EPSS 0.13%
  • Published 17.08.2018 12:29:00
  • Last modified 21.11.2024 04:09:02

Windows Logon Integration feature of F5 BIG-IP APM client prior to version 7.1.7.1 for Windows by default uses Legacy logon mode which uses a SYSTEM account to establish network access. This feature displays a certificate user interface dialog box wh...