QID 375919
Date Published: 2021-10-05
QID 375919: F5 BIG-IP Access Policy Manager (APM) Open Redirect Vulnerability (K32734107)
F5 BIG-IP Access Policy Manager (APM) is a secure, flexible, high-performance solution that provides unified global access to your network, cloud, and applications.
An open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy. This vulnerability allows an unauthenticated malicious user to build an open redirect URI. (CVE-2021-23052)
Vulnerable Component: BIG-IP APM
Affected Versions:
14.1.0 - 14.1.4.3
13.1.0 - 13.1.4
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
An unauthenticated attacker can create an open redirect URI with a specially crafted value and trick BIG-IP APM users into visiting the crafted URI. Victims may be redirected to a malicious website by following the misleading URI.
- K32734107 -
support.f5.com/csp/article/K32734107
CVEs related to QID 375919
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K32734107 |
|