CVE-2022-27634

6.5MEDIUM

Key Information:

Vendor
F5
Vendor
CVE Published:
5 May 2022

Summary

On 16.1.x versions prior to 16.1.2.2 and 15.1.x versions prior to 15.1.5.1, BIG-IP APM does not properly validate configurations, allowing an authenticated attacker with high privileges to manipulate the APM policy leading to privilege escalation/remote code execution. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Affected Version(s)

BIG-IP APM 16.1.x < 16.1.2.2

BIG-IP APM 15.1.x < 15.1.5.1

BIG-IP APM 14.1.x

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.