Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-8022


The Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, and Link Controller 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP AAM 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP AFM and PEM 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP Edge Gateway, WebAccelerator, and WOM 11.x before 11.2.1 HF16 and 11.3.0; and BIG-IP PSM 11.x before 11.2.1 HF16, 11.3.x, and 11.4.x before 11.4.1 HF10 allows remote authenticated users with certain permissions to gain privileges by leveraging an Access Policy Manager customization configuration section that allows file uploads.


Published

2016-08-19T21:59:01.243

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

6.8

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application f5 big-ip_global_traffic_manager 11.0.0 Yes
Application f5 big-ip_global_traffic_manager 11.1.0 Yes
Application f5 big-ip_global_traffic_manager 11.2.0 Yes
Application f5 big-ip_global_traffic_manager 11.2.1 Yes
Application f5 big-ip_global_traffic_manager 11.3.0 Yes
Application f5 big-ip_global_traffic_manager 11.4.0 Yes
Application f5 big-ip_global_traffic_manager 11.4.1 Yes
Application f5 big-ip_global_traffic_manager 11.5.0 Yes
Application f5 big-ip_global_traffic_manager 11.5.1 Yes
Application f5 big-ip_global_traffic_manager 11.5.2 Yes
Application f5 big-ip_global_traffic_manager 11.5.3 Yes
Application f5 big-ip_global_traffic_manager 11.6.0 Yes
Application f5 big-ip_local_traffic_manager 11.0.0 Yes
Application f5 big-ip_local_traffic_manager 11.1.0 Yes
Application f5 big-ip_local_traffic_manager 11.2.0 Yes
Application f5 big-ip_local_traffic_manager 11.2.1 Yes
Application f5 big-ip_local_traffic_manager 11.3.0 Yes
Application f5 big-ip_local_traffic_manager 11.4.0 Yes
Application f5 big-ip_local_traffic_manager 11.4.1 Yes
Application f5 big-ip_local_traffic_manager 11.5.0 Yes
Application f5 big-ip_local_traffic_manager 11.5.1 Yes
Application f5 big-ip_local_traffic_manager 11.5.2 Yes
Application f5 big-ip_local_traffic_manager 11.5.3 Yes
Application f5 big-ip_local_traffic_manager 11.6.0 Yes
Application f5 big-ip_webaccelerator 11.0.0 Yes
Application f5 big-ip_webaccelerator 11.1.0 Yes
Application f5 big-ip_webaccelerator 11.2.0 Yes
Application f5 big-ip_webaccelerator 11.2.1 Yes
Application f5 big-ip_webaccelerator 11.3.0 Yes
Application f5 big-ip_policy_enforcement_manager 11.3.0 Yes
Application f5 big-ip_policy_enforcement_manager 11.4.0 Yes
Application f5 big-ip_policy_enforcement_manager 11.4.1 Yes
Application f5 big-ip_policy_enforcement_manager 11.5.0 Yes
Application f5 big-ip_policy_enforcement_manager 11.5.1 Yes
Application f5 big-ip_policy_enforcement_manager 11.5.2 Yes
Application f5 big-ip_policy_enforcement_manager 11.5.3 Yes
Application f5 big-ip_policy_enforcement_manager 11.6.0 Yes
Application f5 big-ip_advanced_firewall_manager 11.3.0 Yes
Application f5 big-ip_advanced_firewall_manager 11.4.0 Yes
Application f5 big-ip_advanced_firewall_manager 11.4.1 Yes
Application f5 big-ip_advanced_firewall_manager 11.5.0 Yes
Application f5 big-ip_advanced_firewall_manager 11.5.1 Yes
Application f5 big-ip_advanced_firewall_manager 11.5.2 Yes
Application f5 big-ip_advanced_firewall_manager 11.5.3 Yes
Application f5 big-ip_advanced_firewall_manager 11.6.0 Yes
Application f5 big-ip_access_policy_manager 11.0.0 Yes
Application f5 big-ip_access_policy_manager 11.1.0 Yes
Application f5 big-ip_access_policy_manager 11.2.0 Yes
Application f5 big-ip_access_policy_manager 11.2.1 Yes
Application f5 big-ip_access_policy_manager 11.3.0 Yes
Application f5 big-ip_access_policy_manager 11.4.0 Yes
Application f5 big-ip_access_policy_manager 11.4.1 Yes
Application f5 big-ip_access_policy_manager 11.5.0 Yes
Application f5 big-ip_access_policy_manager 11.5.1 Yes
Application f5 big-ip_access_policy_manager 11.5.2 Yes
Application f5 big-ip_access_policy_manager 11.5.3 Yes
Application f5 big-ip_access_policy_manager 11.6.0 Yes
Application f5 big-ip_analytics 11.0.0 Yes
Application f5 big-ip_analytics 11.1.0 Yes
Application f5 big-ip_analytics 11.2.0 Yes
Application f5 big-ip_analytics 11.2.1 Yes
Application f5 big-ip_analytics 11.3.0 Yes
Application f5 big-ip_analytics 11.4.0 Yes
Application f5 big-ip_analytics 11.4.1 Yes
Application f5 big-ip_analytics 11.5.0 Yes
Application f5 big-ip_analytics 11.5.1 Yes
Application f5 big-ip_analytics 11.5.2 Yes
Application f5 big-ip_analytics 11.5.3 Yes
Application f5 big-ip_analytics 11.6.0 Yes
Application f5 big-ip_wan_optimization_manager 11.0.0 Yes
Application f5 big-ip_wan_optimization_manager 11.1.0 Yes
Application f5 big-ip_wan_optimization_manager 11.2.0 Yes
Application f5 big-ip_wan_optimization_manager 11.2.1 Yes
Application f5 big-ip_wan_optimization_manager 11.3.0 Yes
Application f5 big-ip_link_controller 11.0.0 Yes
Application f5 big-ip_link_controller 11.1.0 Yes
Application f5 big-ip_link_controller 11.2.0 Yes
Application f5 big-ip_link_controller 11.2.1 Yes
Application f5 big-ip_link_controller 11.3.0 Yes
Application f5 big-ip_link_controller 11.4.0 Yes
Application f5 big-ip_link_controller 11.4.1 Yes
Application f5 big-ip_link_controller 11.5.0 Yes
Application f5 big-ip_link_controller 11.5.1 Yes
Application f5 big-ip_link_controller 11.5.2 Yes
Application f5 big-ip_link_controller 11.5.3 Yes
Application f5 big-ip_link_controller 11.6.0 Yes
Application f5 big-ip_edge_gateway 11.0.0 Yes
Application f5 big-ip_edge_gateway 11.1.0 Yes
Application f5 big-ip_edge_gateway 11.2.0 Yes
Application f5 big-ip_edge_gateway 11.2.1 Yes
Application f5 big-ip_edge_gateway 11.3.0 Yes
Application f5 big-ip_application_security_manager 11.0.0 Yes
Application f5 big-ip_application_security_manager 11.1.0 Yes
Application f5 big-ip_application_security_manager 11.2.0 Yes
Application f5 big-ip_application_security_manager 11.2.1 Yes
Application f5 big-ip_application_security_manager 11.3.0 Yes
Application f5 big-ip_application_security_manager 11.4.0 Yes
Application f5 big-ip_application_security_manager 11.4.1 Yes
Application f5 big-ip_application_security_manager 11.5.0 Yes
Application f5 big-ip_application_security_manager 11.5.1 Yes
Application f5 big-ip_application_security_manager 11.5.2 Yes
Application f5 big-ip_application_security_manager 11.5.3 Yes
Application f5 big-ip_application_security_manager 11.6.0 Yes
Application f5 big-ip_application_acceleration_manager 11.4.0 Yes
Application f5 big-ip_application_acceleration_manager 11.4.1 Yes
Application f5 big-ip_application_acceleration_manager 11.5.0 Yes
Application f5 big-ip_application_acceleration_manager 11.5.1 Yes
Application f5 big-ip_application_acceleration_manager 11.5.2 Yes
Application f5 big-ip_application_acceleration_manager 11.5.3 Yes
Application f5 big-ip_application_acceleration_manager 11.6.0 Yes
Application f5 big-ip_websafe 11.6.0 Yes
Application f5 big-ip_protocol_security_module 11.0.0 Yes
Application f5 big-ip_protocol_security_module 11.1.0 Yes
Application f5 big-ip_protocol_security_module 11.2.0 Yes
Application f5 big-ip_protocol_security_module 11.2.1 Yes
Application f5 big-ip_protocol_security_module 11.3.0 Yes
Application f5 big-ip_protocol_security_module 11.4.0 Yes
Application f5 big-ip_protocol_security_module 11.4.1 Yes

References