Vulnerabilities > F5 > BIG IP Access Policy Manager > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-09-13 CVE-2018-15310 Information Exposure vulnerability in F5 Big-Ip Access Policy Manager
A vulnerability in BIG-IP APM portal access 11.5.1-11.5.7, 11.6.0-11.6.3, and 12.1.0-12.1.3 discloses the BIG-IP software version in rewritten pages.
network
low complexity
f5 CWE-200
4.3
2018-07-25 CVE-2018-5537 Improper Input Validation vulnerability in F5 products
A remote attacker may be able to disrupt services on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.2.1-11.5.6 if the TMM virtual server is configured with a HTML or a Rewrite profile.
network
high complexity
f5 CWE-20
5.3
2018-07-19 CVE-2018-5532 Unspecified vulnerability in F5 products
On F5 BIG-IP 13.0.0, 12.1.0-12.1.2, 11.6.0-11.6.3.1, or 11.2.1-11.5.6 a domain name cached within the DNS Cache of TMM may continue to be resolved by the cache even after the parent server revokes the record, if the DNS Cache is receiving a stream of requests for the cached name.
network
low complexity
f5
5.3
2018-06-27 CVE-2018-5528 Improper Input Validation vulnerability in F5 Big-Ip Access Policy Manager
Under certain conditions, TMM may restart and produce a core file while processing APM data on BIG-IP 13.0.1 or 13.1.0.4-13.1.0.7.
network
high complexity
f5 CWE-20
5.3
2018-06-01 CVE-2018-5525 Information Exposure vulnerability in F5 products
A local file vulnerability exists in the F5 BIG-IP Configuration utility on versions 13.0.0, 12.1.0-12.1.2, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 that exposes files containing F5-provided data only and do not include any configuration data, proxied traffic, or other potentially sensitive customer data.
network
low complexity
f5 CWE-200
4.3
2018-06-01 CVE-2018-5524 Unspecified vulnerability in F5 products
Under certain conditions, on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, or 11.6.1 HF2-11.6.3.1, virtual servers configured with Client SSL or Server SSL profiles which make use of network hardware security module (HSM) functionality are exposed and impacted by this issue.
network
low complexity
f5
5.3
2018-06-01 CVE-2018-5522 Improper Input Validation vulnerability in F5 products
On F5 BIG-IP 13.0.0, 12.0.0-12.1.2, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, when processing DIAMETER transactions with carefully crafted attribute-value pairs, TMM may crash.
network
high complexity
f5 CWE-20
5.9
2018-06-01 CVE-2018-5521 Cross-site Scripting vulnerability in F5 products
On F5 BIG-IP 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, carefully crafted URLs can be used to reflect arbitrary content into GeoIP lookup responses, potentially exposing clients to XSS.
network
low complexity
f5 CWE-79
6.1
2018-06-01 CVE-2017-6153 Resource Exhaustion vulnerability in F5 products
Features in F5 BIG-IP 13.0.0-13.1.0.3, 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 system that utilizes inflate functionality directly, via an iRule, or via the inflate code from PEM module are subjected to a service disruption via a "Zip Bomb" attack.
network
low complexity
f5 CWE-400
5.3
2018-05-02 CVE-2018-5520 Incorrect Authorization vulnerability in F5 products
On an F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, or 11.2.1-11.6.3.1 system configured in Appliance mode, the TMOS Shell (tmsh) may allow an administrative user to use the dig utility to gain unauthorized access to file system resources.
network
high complexity
f5 CWE-863
4.4