4
CVSSv2

CVE-2012-2997

Published: 21/01/2014 Updated: 29/08/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

XML External Entity (XXE) vulnerability in sam/admin/vpe2/public/php/server.php in F5 BIG-IP 10.0.0 up to and including 10.2.4 and 11.0.0 up to and including 11.2.1 allows remote authenticated users to read arbitrary files via a crafted XML file.

Vulnerable Product Search on Vulmon Subscribe to Product

f5 big-ip configuration utility 10.0.0

f5 big-ip configuration utility 10.2.4

f5 big-ip configuration utility 11.0.0

f5 big-ip configuration utility 11.2.1

Exploits

source: wwwsecurityfocuscom/bid/57496/info F5 Networks BIG-IP is prone to an XML External Entity injection vulnerability Attackers can exploit this issue to obtain potentially sensitive information from local files on computers running the vulnerable application and to carry out other attacks POST /sam/admin/vpe2/public/php/serverph ...
F5 BIG-IP versions 1120 and below suffer from an XML external entity injection (XXE) vulnerability ...