Vulnerabilities > F5 > BIG IP Access Policy Manager > 16.1.2

DATE CVE VULNERABILITY TITLE RISK
2022-01-25 CVE-2022-23032 Origin Validation Error vulnerability in F5 Big-Ip Access Policy Manager
In all versions before 7.2.1.4, when proxy settings are configured in the network access resource of a BIG-IP APM system, connecting BIG-IP Edge Client on Mac and Windows is vulnerable to a DNS rebinding attack.
network
low complexity
f5 CWE-346
5.3
2021-11-11 CVE-2002-20001 Resource Exhaustion vulnerability in multiple products
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack.
network
low complexity
balasys siemens suse f5 hpe stormshield CWE-400
7.5