CVE-2022-41617
- EPSS 4.44%
- Veröffentlicht 19.10.2022 22:15:12
- Zuletzt bearbeitet 21.11.2024 07:23:30
In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, When the Advanced WAF / ASM module is provisioned, an authenticated remote code execution vulnerability exists in the BIG-IP iControl REST...
CVE-2022-41691
- EPSS 0.68%
- Veröffentlicht 19.10.2022 22:15:12
- Zuletzt bearbeitet 21.11.2024 07:23:39
When a BIG-IP Advanced WAF/ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.
CVE-2022-29491
- EPSS 1.04%
- Veröffentlicht 05.05.2022 17:15:15
- Zuletzt bearbeitet 21.11.2024 06:59:10
On F5 BIG-IP LTM, Advanced WAF, ASM, or APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, and all versions of 13.1.x, 12.1.x, and 11.6.x, when a virtual server is configured with HTTP, TCP on o...
CVE-2022-27806
- EPSS 0.66%
- Veröffentlicht 05.05.2022 17:15:13
- Zuletzt bearbeitet 21.11.2024 06:56:13
On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP Advanced WAF, ASM, and ASM, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, when running in Appliance mode, an authenticated attacker assigned the A...
CVE-2022-26890
- EPSS 0.89%
- Veröffentlicht 05.05.2022 17:15:12
- Zuletzt bearbeitet 21.11.2024 06:54:44
On F5 BIG-IP Advanced WAF, ASM, and APM 16.1.x versions prior to 16.1.2.1, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when ASM or Advanced WAF, as well as APM, are configured on a virtual ...
CVE-2022-25946
- EPSS 0.13%
- Veröffentlicht 05.05.2022 17:15:11
- Zuletzt bearbeitet 21.11.2024 06:53:15
On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP Advanced WAF, ASM, and ASM, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, when running in Appliance mode, an authenticated attacker with Administr...
CVE-2022-23031
- EPSS 0.37%
- Veröffentlicht 25.01.2022 20:15:10
- Zuletzt bearbeitet 21.11.2024 06:47:50
On BIG-IP FPS, ASM, and Advanced WAF versions 16.1.x before 16.1.1, 15.1.x before 15.1.4, and 14.1.x before 14.1.4.4, an XML External Entity (XXE) vulnerability exists in an undisclosed page of the F5 Advanced Web Application Firewall (Advanced WAF) ...
CVE-2022-23023
- EPSS 0.32%
- Veröffentlicht 25.01.2022 20:15:09
- Zuletzt bearbeitet 21.11.2024 06:47:49
On BIG-IP version 16.1.x before 16.1.2.1, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, and BIG-IQ all versions of 8.x and 7.x, undisclosed requests by an authenticated iControl REST user can cause an increase i...
CVE-2022-23025
- EPSS 0.75%
- Veröffentlicht 25.01.2022 20:15:09
- Zuletzt bearbeitet 21.11.2024 06:47:49
On BIG-IP version 16.1.x before 16.1.1, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, when a SIP ALG profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to ter...
CVE-2022-23026
- EPSS 0.3%
- Veröffentlicht 25.01.2022 20:15:09
- Zuletzt bearbeitet 21.11.2024 06:47:50
On BIG-IP ASM & Advanced WAF version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, an authenticated user with low privileges, such as a guest, can upload data using an undisclosed REST en...