Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-31473


In BIG-IP Versions 16.1.x before 16.1.1 and 15.1.x before 15.1.4, when running in Appliance mode, an authenticated attacker may be able to bypass Appliance mode restrictions due to a directory traversal vulnerability in an undisclosed page within iApps. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.


Published

2022-08-04T18:15:09.630

Last Modified

2024-11-21T07:04:31.587

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.8 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application f5 big-ip_access_policy_manager < 15.1.4 Yes
Application f5 big-ip_access_policy_manager 16.1.0 Yes

References