Open Redirect Vulnerability in F5 BIG-IP APM by F5 Networks
CVE-2020-27729
6.1MEDIUM
Summary
Certain versions of F5 BIG-IP APM expose an open redirect vulnerability through an undisclosed link on the virtual server. This flaw allows a malicious actor to manipulate and construct a redirect URI that could lead users to unauthorized destinations, thereby risking sensitive information and system integrity. It is crucial to patch these affected versions to mitigate potential exploits.
Affected Version(s)
BIG-IP APM 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, 11.6.1-11.6.5.2
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved