Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
f5 big-ip application security manager vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2021-23036
On version 16.0.x prior to 16.0.1.2, when a BIG-IP ASM and DataSafe profile are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not...
F5 Big-ip Advanced Web Application Firewall
F5 Big-ip Application Security Manager
F5 Big-ip Datasafe
7.5
CVSSv3
CVE-2022-26071
On F5 BIG-IP 16.1.x versions before 16.1.2.2, 15.1.x versions before 15.1.5.1, 14.1.x versions before 14.1.4.6, 13.1.x versions before 13.1.5, and all versions of 12.1.x and 11.6.x, a flaw in the way reply ICMP packets are limited in the Traffic Management Microkernel (TMM) allow...
F5 Big-ip Local Traffic Manager 11.6.1
F5 Big-ip Local Traffic Manager 12.1.2
F5 Big-ip Advanced Firewall Manager 12.1.0
F5 Big-ip Access Policy Manager 12.1.2
F5 Big-ip Global Traffic Manager 11.6.1
F5 Big-ip Domain Name System 12.1.2
F5 Big-ip Policy Enforcement Manager 12.1.1
F5 Big-ip Policy Enforcement Manager 12.1.2
F5 Big-ip Advanced Firewall Manager 12.1.2
F5 Big-ip Application Security Manager 12.1.1
F5 Big-ip Local Traffic Manager 12.1.0
F5 Big-ip Analytics 11.6.1
F5 Big-ip Application Acceleration Manager 12.1.0
F5 Big-ip Link Controller 12.1.1
F5 Big-ip Analytics 12.1.0
F5 Big-ip Application Acceleration Manager 11.6.1
F5 Big-ip Access Policy Manager 12.1.1
F5 Big-ip Link Controller 12.1.0
F5 Big-ip Application Acceleration Manager 12.1.1
F5 Big-ip Link Controller 11.6.1
F5 Big-ip Link Controller 12.1.2
F5 Big-ip Advanced Firewall Manager 12.1.1
7.5
CVSSv3
CVE-2022-26372
On F5 BIG-IP 15.1.x versions before 15.1.0.2, 14.1.x versions before 14.1.4.6, 13.1.x versions before 13.1.5, and all versions of 12.1.x and 11.6.x, when a DNS listener is configured on a virtual server with DNS queueing (default), undisclosed requests can cause an increase in me...
F5 Big-ip Local Traffic Manager 11.6.1
F5 Big-ip Local Traffic Manager 12.1.2
F5 Big-ip Advanced Firewall Manager 12.1.0
F5 Big-ip Access Policy Manager 12.1.2
F5 Big-ip Global Traffic Manager 11.6.1
F5 Big-ip Domain Name System 12.1.2
F5 Big-ip Policy Enforcement Manager 12.1.1
F5 Big-ip Policy Enforcement Manager 12.1.2
F5 Big-ip Advanced Firewall Manager 12.1.2
F5 Big-ip Application Security Manager 12.1.1
F5 Big-ip Local Traffic Manager 12.1.0
F5 Big-ip Analytics 11.6.1
F5 Big-ip Application Acceleration Manager 12.1.0
F5 Big-ip Link Controller 12.1.1
F5 Big-ip Analytics 12.1.0
F5 Big-ip Application Acceleration Manager 11.6.1
F5 Big-ip Access Policy Manager 12.1.1
F5 Big-ip Link Controller 12.1.0
F5 Big-ip Application Acceleration Manager 12.1.1
F5 Big-ip Link Controller 11.6.1
F5 Big-ip Link Controller 12.1.2
F5 Big-ip Advanced Firewall Manager 12.1.1
7.5
CVSSv3
CVE-2022-27189
On F5 BIG-IP 16.1.x versions before 16.1.2.2, 15.1.x versions before 15.1.5.1, 14.1.x versions before 14.1.4.6, 13.1.x versions before 13.1.5, and all versions of 12.1.x and 11.6.x, when an Internet Content Adaptation Protocol (ICAP) profile is configured on a virtual server, und...
F5 Big-ip Local Traffic Manager 11.6.1
F5 Big-ip Local Traffic Manager 12.1.2
F5 Big-ip Advanced Firewall Manager 12.1.0
F5 Big-ip Access Policy Manager 12.1.2
F5 Big-ip Global Traffic Manager 11.6.1
F5 Big-ip Domain Name System 12.1.2
F5 Big-ip Policy Enforcement Manager 12.1.1
F5 Big-ip Policy Enforcement Manager 12.1.2
F5 Big-ip Advanced Firewall Manager 12.1.2
F5 Big-ip Application Security Manager 12.1.1
F5 Big-ip Local Traffic Manager 12.1.0
F5 Big-ip Analytics 11.6.1
F5 Big-ip Application Acceleration Manager 12.1.0
F5 Big-ip Link Controller 12.1.1
F5 Big-ip Analytics 12.1.0
F5 Big-ip Application Acceleration Manager 11.6.1
F5 Big-ip Access Policy Manager 12.1.1
F5 Big-ip Link Controller 12.1.0
F5 Big-ip Application Acceleration Manager 12.1.1
F5 Big-ip Link Controller 11.6.1
F5 Big-ip Link Controller 12.1.2
F5 Big-ip Advanced Firewall Manager 12.1.1
4.3
CVSSv3
CVE-2022-29474
On F5 BIG-IP 16.1.x versions before 16.1.2.2, 15.1.x versions before 15.1.5.1, 14.1.x versions before 14.1.4.6, 13.1.x versions before 13.1.5, and all versions of 12.1.x and 11.6.x, a directory traversal vulnerability exists in iControl SOAP that allows an authenticated attacker ...
F5 Big-ip Local Traffic Manager 11.6.1
F5 Big-ip Local Traffic Manager 12.1.2
F5 Big-ip Advanced Firewall Manager 12.1.0
F5 Big-ip Access Policy Manager 12.1.2
F5 Big-ip Global Traffic Manager 11.6.1
F5 Big-ip Domain Name System 12.1.2
F5 Big-ip Policy Enforcement Manager 12.1.1
F5 Big-ip Policy Enforcement Manager 12.1.2
F5 Big-ip Advanced Firewall Manager 12.1.2
F5 Big-ip Application Security Manager 12.1.1
F5 Big-ip Local Traffic Manager 12.1.0
F5 Big-ip Analytics 11.6.1
F5 Big-ip Application Acceleration Manager 12.1.0
F5 Big-ip Link Controller 12.1.1
F5 Big-ip Analytics 12.1.0
F5 Big-ip Application Acceleration Manager 11.6.1
F5 Big-ip Access Policy Manager 12.1.1
F5 Big-ip Link Controller 12.1.0
F5 Big-ip Application Acceleration Manager 12.1.1
F5 Big-ip Link Controller 11.6.1
F5 Big-ip Link Controller 12.1.2
F5 Big-ip Advanced Firewall Manager 12.1.1
5.3
CVSSv3
CVE-2022-29480
On F5 BIG-IP 13.1.x versions before 13.1.5, and all versions of 12.1.x and 11.6.x, when multiple route domains are configured, undisclosed requests to big3d can cause an increase in CPU resource utilization. Note: Software versions which have reached End of Technical Support (EoT...
F5 Big-ip Local Traffic Manager 11.6.1
F5 Big-ip Local Traffic Manager 12.1.2
F5 Big-ip Advanced Firewall Manager 12.1.0
F5 Big-ip Access Policy Manager 12.1.2
F5 Big-ip Global Traffic Manager 11.6.1
F5 Big-ip Domain Name System 12.1.2
F5 Big-ip Policy Enforcement Manager 12.1.1
F5 Big-ip Policy Enforcement Manager 12.1.2
F5 Big-ip Advanced Firewall Manager 12.1.2
F5 Big-ip Application Security Manager 12.1.1
F5 Big-ip Local Traffic Manager 12.1.0
F5 Big-ip Analytics 11.6.1
F5 Big-ip Application Acceleration Manager 12.1.0
F5 Big-ip Link Controller 12.1.1
F5 Big-ip Analytics 12.1.0
F5 Big-ip Application Acceleration Manager 11.6.1
F5 Big-ip Access Policy Manager 12.1.1
F5 Big-ip Link Controller 12.1.0
F5 Big-ip Application Acceleration Manager 12.1.1
F5 Big-ip Link Controller 11.6.1
F5 Big-ip Link Controller 12.1.2
F5 Big-ip Advanced Firewall Manager 12.1.1
4.9
CVSSv3
CVE-2022-26835
On F5 BIG-IP 16.1.x versions before 16.1.2.2, 15.1.x versions before 15.1.5.1, 14.1.x versions before 14.1.4.6, 13.1.x versions before 13.1.5, and all versions of 12.1.x and 11.6.x, directory traversal vulnerabilities exist in undisclosed iControl REST endpoints and TMOS Shell (t...
F5 Big-ip Local Traffic Manager 11.6.1
F5 Big-ip Local Traffic Manager 12.1.2
F5 Big-ip Advanced Firewall Manager 12.1.0
F5 Big-ip Access Policy Manager 12.1.2
F5 Big-ip Global Traffic Manager 11.6.1
F5 Big-ip Domain Name System 12.1.2
F5 Big-ip Policy Enforcement Manager 12.1.1
F5 Big-ip Policy Enforcement Manager 12.1.2
F5 Big-ip Advanced Firewall Manager 12.1.2
F5 Big-ip Application Security Manager 12.1.1
F5 Big-ip Local Traffic Manager 12.1.0
F5 Big-ip Analytics 11.6.1
F5 Big-ip Application Acceleration Manager 12.1.0
F5 Big-ip Link Controller 12.1.1
F5 Big-ip Analytics 12.1.0
F5 Big-ip Application Acceleration Manager 11.6.1
F5 Big-ip Access Policy Manager 12.1.1
F5 Big-ip Link Controller 12.1.0
F5 Big-ip Application Acceleration Manager 12.1.1
F5 Big-ip Link Controller 11.6.1
F5 Big-ip Link Controller 12.1.2
F5 Big-ip Advanced Firewall Manager 12.1.1
4.3
CVSSv3
CVE-2022-1389
On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP (fixed in 17.0.0), a cross-site request forgery (CSRF) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. This vulnerability allows an malicious user to run a limited ...
F5 Big-ip Local Traffic Manager 11.6.1
F5 Big-ip Local Traffic Manager 12.1.2
F5 Big-ip Advanced Firewall Manager 12.1.0
F5 Big-ip Access Policy Manager 12.1.2
F5 Big-ip Global Traffic Manager 11.6.1
F5 Big-ip Domain Name System 12.1.2
F5 Big-ip Policy Enforcement Manager 12.1.1
F5 Big-ip Policy Enforcement Manager 12.1.2
F5 Big-ip Advanced Firewall Manager 12.1.2
F5 Big-ip Application Security Manager 12.1.1
F5 Big-ip Local Traffic Manager 12.1.0
F5 Big-ip Analytics 11.6.1
F5 Big-ip Application Acceleration Manager 12.1.0
F5 Big-ip Link Controller 12.1.1
F5 Big-ip Analytics 12.1.0
F5 Big-ip Application Acceleration Manager 11.6.1
F5 Big-ip Access Policy Manager 12.1.1
F5 Big-ip Link Controller 12.1.0
F5 Big-ip Application Acceleration Manager 12.1.1
F5 Big-ip Link Controller 11.6.1
F5 Big-ip Link Controller 12.1.2
F5 Big-ip Advanced Firewall Manager 12.1.1
4.3
CVSSv3
CVE-2022-1468
On all versions of 17.0.x, 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x on F5 BIG-IP, an authenticated iControl REST user with at least guest role privileges can cause processing delays to iControl REST requests via undisclosed requests. Note: Software versions which have r...
F5 Big-ip Local Traffic Manager 11.6.1
F5 Big-ip Local Traffic Manager 12.1.2
F5 Big-ip Advanced Firewall Manager 12.1.0
F5 Big-ip Access Policy Manager 12.1.2
F5 Big-ip Global Traffic Manager 11.6.1
F5 Big-ip Domain Name System 12.1.2
F5 Big-ip Policy Enforcement Manager 12.1.1
F5 Big-ip Policy Enforcement Manager 12.1.2
F5 Big-ip Advanced Firewall Manager 12.1.2
F5 Big-ip Application Security Manager 12.1.1
F5 Big-ip Local Traffic Manager 12.1.0
F5 Big-ip Analytics 11.6.1
F5 Big-ip Application Acceleration Manager 12.1.0
F5 Big-ip Link Controller 12.1.1
F5 Big-ip Analytics 12.1.0
F5 Big-ip Application Acceleration Manager 11.6.1
F5 Big-ip Access Policy Manager 12.1.1
F5 Big-ip Link Controller 12.1.0
F5 Big-ip Application Acceleration Manager 12.1.1
F5 Big-ip Link Controller 11.6.1
F5 Big-ip Link Controller 12.1.2
F5 Big-ip Advanced Firewall Manager 12.1.1
5.3
CVSSv3
CVE-2016-6249
F5 BIG-IP 12.0.0 and 11.5.0 - 11.6.1 REST requests which timeout during user account authentication may log sensitive attributes such as passwords in plaintext to /var/log/restjavad.0.log. It may allow local users to obtain sensitive information by reading these files.
F5 Big-ip Local Traffic Manager 11.6.1
F5 Big-ip Websafe 11.6.1
F5 Big-ip Global Traffic Manager 11.6.1
F5 Big-ip Advanced Firewall Manager 11.5.4
F5 Big-ip Link Controller 11.5.3
F5 Big-ip Analytics 11.6.0
F5 Big-ip Access Policy Manager 11.5.2
F5 Big-ip Application Acceleration Manager 11.5.2
F5 Big-ip Local Traffic Manager 12.0.0
F5 Big-ip Link Controller 11.5.1
F5 Big-ip Websafe 11.5.1
F5 Big-ip Websafe 11.6.0
F5 Big-ip Application Security Manager 11.5.1
F5 Big-ip Application Security Manager 11.6.0
F5 Big-ip Policy Enforcement Manager 11.5.2
F5 Big-ip Policy Enforcement Manager 11.5.0
F5 Big-ip Policy Enforcement Manager 12.0.0
F5 Big-ip Access Policy Manager 11.5.0
F5 Big-ip Global Traffic Manager 11.5.1
F5 Big-ip Application Acceleration Manager 12.0.0
F5 Big-ip Access Policy Manager 12.0.0
F5 Big-ip Link Controller 11.5.2
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
path traversal
CVE-2024-33545
CVE-2024-35725
CVE-2024-32704
overflow
file upload
CVE-2024-0230
CVE-2024-32705
CVE-2024-23692
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »