BIG-IP APM OAuth vulnerability
CVE-2023-22341

7.5HIGH

Key Information:

Vendor

F5

Status
Vendor
CVE Published:
1 February 2023

What is CVE-2023-22341?

A vulnerability exists in the BIG-IP APM system by F5 Networks, impacting versions 14.1.x prior to 14.1.5.3 and all versions of 13.1.x. This issue can occur when the system is configured with an OAuth Server referring to an OAuth Provider, an OAuth profile set to an Authorization Endpoint of '/', and an access profile linked to the aforementioned OAuth profile associated with an HTTPS virtual server. Undisclosed requests under these configurations may result in the termination of the Traffic Management Microkernel (TMM).

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

BIG-IP 14.1.0 < 14.1.5.3

BIG-IP 13.1.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.