F5 BIG-IQ Cloud and Security 4.0.0 up to and including 4.1.0 allows remote authenticated users to change the password of arbitrary users via the name parameter in a request to the user's page in mgmt/shared/authz/users/.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
f5 big-iq 4.1.0.2013.0 |