7.5
CVSSv3

CVE-2015-8022

Published: 19/08/2016 Updated: 06/06/2019
CVSS v2 Base Score: 8.5 | Impact Score: 10 | Exploitability Score: 6.8
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 756
Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Summary

The Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, and Link Controller 11.x prior to 11.2.1 HF16, 11.3.x, 11.4.x prior to 11.4.1 HF10, 11.5.x prior to 11.5.4, and 11.6.x prior to 11.6.1; BIG-IP AAM 11.4.x prior to 11.4.1 HF10, 11.5.x prior to 11.5.4, and 11.6.x prior to 11.6.1; BIG-IP AFM and PEM 11.3.x, 11.4.x prior to 11.4.1 HF10, 11.5.x prior to 11.5.4, and 11.6.x prior to 11.6.1; BIG-IP Edge Gateway, WebAccelerator, and WOM 11.x prior to 11.2.1 HF16 and 11.3.0; and BIG-IP PSM 11.x prior to 11.2.1 HF16, 11.3.x, and 11.4.x prior to 11.4.1 HF10 allows remote authenticated users with certain permissions to gain privileges by leveraging an Access Policy Manager customization configuration section that allows file uploads.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

f5 big-ip global traffic manager 11.2.0

f5 big-ip global traffic manager 11.1.0

f5 big-ip global traffic manager 11.0.0

f5 big-ip global traffic manager 11.5.3

f5 big-ip global traffic manager 11.5.2

f5 big-ip global traffic manager 11.5.1

f5 big-ip global traffic manager 11.5.0

f5 big-ip global traffic manager 11.4.0

f5 big-ip global traffic manager 11.2.1

f5 big-ip global traffic manager 11.6.0

f5 big-ip global traffic manager 11.4.1

f5 big-ip global traffic manager 11.3.0

f5 big-ip local traffic manager 11.6.0

f5 big-ip local traffic manager 11.4.1

f5 big-ip local traffic manager 11.4.0

f5 big-ip local traffic manager 11.3.0

f5 big-ip local traffic manager 11.1.0

f5 big-ip local traffic manager 11.5.2

f5 big-ip local traffic manager 11.5.0

f5 big-ip local traffic manager 11.0.0

f5 big-ip local traffic manager 11.2.1

f5 big-ip local traffic manager 11.5.3

f5 big-ip local traffic manager 11.5.1

f5 big-ip local traffic manager 11.2.0

f5 big-ip webaccelerator 11.3.0

f5 big-ip webaccelerator 11.2.1

f5 big-ip webaccelerator 11.2.0

f5 big-ip webaccelerator 11.1.0

f5 big-ip webaccelerator 11.0.0

f5 big-ip policy enforcement manager 11.5.1

f5 big-ip policy enforcement manager 11.5.0

f5 big-ip policy enforcement manager 11.4.1

f5 big-ip policy enforcement manager 11.4.0

f5 big-ip policy enforcement manager 11.5.3

f5 big-ip policy enforcement manager 11.6.0

f5 big-ip policy enforcement manager 11.5.2

f5 big-ip policy enforcement manager 11.3.0

f5 big-ip advanced firewall manager 11.5.2

f5 big-ip advanced firewall manager 11.5.1

f5 big-ip advanced firewall manager 11.5.0

f5 big-ip advanced firewall manager 11.4.1

f5 big-ip advanced firewall manager 11.5.3

f5 big-ip advanced firewall manager 11.4.0

f5 big-ip advanced firewall manager 11.6.0

f5 big-ip advanced firewall manager 11.3.0

f5 big-ip access policy manager 11.1.0

f5 big-ip access policy manager 11.0.0

f5 big-ip access policy manager 11.5.3

f5 big-ip access policy manager 11.5.2

f5 big-ip access policy manager 11.5.1

f5 big-ip access policy manager 11.5.0

f5 big-ip access policy manager 11.4.0

f5 big-ip access policy manager 11.2.1

f5 big-ip access policy manager 11.6.0

f5 big-ip access policy manager 11.4.1

f5 big-ip access policy manager 11.3.0

f5 big-ip access policy manager 11.2.0

f5 big-ip analytics 11.6.0

f5 big-ip analytics 11.4.1

f5 big-ip analytics 11.4.0

f5 big-ip analytics 11.3.0

f5 big-ip analytics 11.2.1

f5 big-ip analytics 11.5.2

f5 big-ip analytics 11.5.0

f5 big-ip analytics 11.2.0

f5 big-ip analytics 11.0.0

f5 big-ip analytics 11.5.3

f5 big-ip analytics 11.5.1

f5 big-ip analytics 11.1.0

f5 big-ip wan optimization manager 11.0.0

f5 big-ip wan optimization manager 11.1.0

f5 big-ip wan optimization manager 11.2.1

f5 big-ip wan optimization manager 11.2.0

f5 big-ip wan optimization manager 11.3.0

f5 big-ip link controller 11.0.0

f5 big-ip link controller 11.5.1

f5 big-ip link controller 11.5.0

f5 big-ip link controller 11.4.1

f5 big-ip link controller 11.4.0

f5 big-ip link controller 11.5.3

f5 big-ip link controller 11.2.1

f5 big-ip link controller 11.1.0

f5 big-ip link controller 11.6.0

f5 big-ip link controller 11.5.2

f5 big-ip link controller 11.3.0

f5 big-ip link controller 11.2.0

f5 big-ip edge gateway 11.0.0

f5 big-ip edge gateway 11.1.0

f5 big-ip edge gateway 11.2.0

f5 big-ip edge gateway 11.3.0

f5 big-ip edge gateway 11.2.1

f5 big-ip application security manager 11.2.0

f5 big-ip application security manager 11.1.0

f5 big-ip application security manager 11.0.0

f5 big-ip application security manager 11.6.0

f5 big-ip application security manager 11.5.3

f5 big-ip application security manager 11.5.2

f5 big-ip application security manager 11.5.1

f5 big-ip application security manager 11.4.1

f5 big-ip application security manager 11.5.0

f5 big-ip application security manager 11.3.0

f5 big-ip application security manager 11.4.0

f5 big-ip application security manager 11.2.1

f5 big-ip application acceleration manager 11.5.0

f5 big-ip application acceleration manager 11.4.1

f5 big-ip application acceleration manager 11.4.0

f5 big-ip application acceleration manager 11.5.3

f5 big-ip application acceleration manager 11.5.1

f5 big-ip application acceleration manager 11.6.0

f5 big-ip application acceleration manager 11.5.2

f5 big-ip websafe 11.6.0

f5 big-ip protocol security module 11.3.0

f5 big-ip protocol security module 11.2.1

f5 big-ip protocol security module 11.2.0

f5 big-ip protocol security module 11.1.0

f5 big-ip protocol security module 11.0.0

f5 big-ip protocol security module 11.4.0

f5 big-ip protocol security module 11.4.1