CVE-2018-15316

5.5MEDIUM

Key Information:

Vendor
F5
Vendor
CVE Published:
19 October 2018

Summary

In F5 BIG-IP APM 13.0.0-13.1.1.1, APM Client 7.1.5-7.1.6, and/or Edge Client 7101-7160, the BIG-IP APM Edge Client component loads the policy library with user permission and bypassing the endpoint checks.

Affected Version(s)

BIG-IP (APM) 13.0.0-13.1.1.1

BIG-IP APM Clients 7.1.5 - 7.1.6

BIG-IP Edge Client 7101 - 7160

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.