QID 375687
Date Published: 2021-11-15
QID 375687: F5 BIG-IP Access Policy Manager (APM) ACL Bypass Vulnerability (K75540265)
F5 BIG-IP Access Policy Manager (APM) is a secure, flexible, high-performance solution that provides unified global access to your network, cloud, and applications.
An attacker may be able to bypass APM's internal restrictions and retrieve static content that is hosted within APM by sending specifically crafted requests to an APM Virtual Server. CVE-2021-23016
Vulnerable Component: BIG-IP APM
Affected Versions:
16.0.0 - 16.0.1
15.1.0 - 15.1.2
14.1.0 - 14.1.4
13.1.0 - 13.1.3
12.1.0 - 12.1.5
12.1.0 - 12.1.6
11.6.1 - 11.6.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
This vulnerability may allow an attacker to retrieve static content hosted on the BIG-IP system that they would otherwise not be able to, allowing them to more effectively fingerprint a device. It does not allow any modification of data nor the exposure of any sensitive information or personally identifiable information (PII) in the standard, default, or recommended configurations.
- K75540265 -
support.f5.com/csp/article/K75540265
CVEs related to QID 375687
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K75540265 |
|