CVE-2015-8022
7.5
Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.6 / Impact: 5.9
Source: NVD
Description
The Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, and Link Controller 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP AAM 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP AFM and PEM 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP Edge Gateway, WebAccelerator, and WOM 11.x before 11.2.1 HF16 and 11.3.0; and BIG-IP PSM 11.x before 11.2.1 HF16, 11.3.x, and 11.4.x before 11.4.1 HF10 allows remote authenticated users with certain permissions to gain privileges by leveraging an Access Policy Manager customization configuration section that allows file uploads.
Affected (118)
Products: F5: Big Ip Global Traffic Manager, Big Ip Local Traffic Manager, Big Ip Webaccelerator, Big Ip Policy Enforcement Manager, Big Ip Advanced Firewall Manager, Big Ip Access Policy Manager, Big Ip Analytics, Big Ip Wan Optimization Manager, Big Ip Link Controller, Big Ip Edge Gateway, Big Ip Application Security Manager, Big Ip Application Acceleration Manager, Big Ip Websafe, Big Ip Protocol Security Module
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.0.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.0.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.0.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.3.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.3.0 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.0.0 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.0.0 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.0.0 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.0.0 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.0.0 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.0.0 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.4.0 |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.6.0 |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.0.0 |
Related CWEs
References (4)
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.