Memory Resource Utilization Vulnerability in F5 BIG-IP with SAML Configuration
CVE-2025-47148

7.1HIGH

Key Information:

Vendor

F5

Status
Vendor
CVE Published:
15 October 2025

What is CVE-2025-47148?

The F5 BIG-IP system, when configured as both a Security Assertion Markup Language (SAML) service provider and Identity Provider with single logout (SLO) enabled on its access policies, may experience an increase in memory resource utilization due to undisclosed requests. This issue can impact performance and stability, making it crucial for administrators to monitor their configurations and apply necessary patches.

Affected Version(s)

BIG-IP 17.5.0 < 17.5.1

BIG-IP 17.1.0 < 17.1.3

BIG-IP 16.1.0 < 16.1.6.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

F5
.