On BIG-IP AAM 13.0.0 or 12.1.0-12.1.3.7, the dcdb_convert utility used by BIG-IP AAM fails to drop group permissions when executing helper scripts, which could be used to leverage attacks against the BIG-IP system.
2018-12-20T20:29:00.357
2024-11-21T03:50:34.890
Modified
CVSSv3.0: 7.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | f5 | big-ip_application_acceleration_manager | ≤ 12.1.3 | Yes |
Application | f5 | big-ip_application_acceleration_manager | 13.0.0 | Yes |