F5

Big-ip Application Security Manager

492 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.39%
  • Published 14.09.2021 22:15:07
  • Last modified 21.11.2024 05:51:10

On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, and 14.1.x before 14.1.4.3, a DOM based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScrip...

  • EPSS 1.12%
  • Published 14.09.2021 21:15:07
  • Last modified 21.11.2024 05:51:10

On version 15.1.x before 15.1.0.5, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all versions of 12.1.x and 11.6.x, an authenticated remote command execution vulnerability exists in the BIG-IP Configuration utility. Note: Software versions whic...

  • EPSS 0.61%
  • Published 14.09.2021 21:15:07
  • Last modified 21.11.2024 05:51:10

On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, and 13.1.x before 13.1.4, when JSON content profiles are configured for URLs as part of an F5 Advanced Web Application Firewall (WAF)/BIG-IP ASM security policy and ap...

  • EPSS 0.68%
  • Published 14.09.2021 21:15:07
  • Last modified 21.11.2024 05:51:11

On BIG-IP Advanced WAF and BIG-IP ASM version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all versions of 12.1.x, when a WebSocket profile is configured on a virtual server, undisclosed requests...

  • EPSS 0.5%
  • Published 14.09.2021 19:15:07
  • Last modified 21.11.2024 05:51:11

On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.1, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and 11.6.x before 11.6.5.3, an authenticated user may perform a privilege escalation on the BIG-IP Advanced WAF and ASM Confi...

  • EPSS 0.61%
  • Published 14.09.2021 19:15:07
  • Last modified 21.11.2024 05:51:11

On version 16.0.x before 16.0.1.2, when a BIG-IP ASM and DataSafe profile are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Tech...

  • EPSS 0.65%
  • Published 14.09.2021 18:15:08
  • Last modified 21.11.2024 05:51:11

On BIG-IP Advanced WAF and BIG-IP ASM version 16.x before 16.1.0x, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all versions of 12.1.x, when a WebSocket profile is configured on a virtual server, undisclosed requests ca...

  • EPSS 0.92%
  • Published 14.09.2021 18:15:08
  • Last modified 21.11.2024 05:51:11

On BIG-IP version 16.x before 16.1.0 and 15.1.x before 15.1.3.1, when a DNS profile using a DNS cache resolver is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Soft...

  • EPSS 0.86%
  • Published 14.09.2021 18:15:08
  • Last modified 21.11.2024 05:51:11

On BIG-IP 14.1.x before 14.1.4.4, when an HTTP profile is configured on a virtual server, after a specific sequence of packets, chunked responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reac...

  • EPSS 0.71%
  • Published 14.09.2021 18:15:08
  • Last modified 21.11.2024 05:51:11

On all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the...