QID 376050
QID 376050: F5 BIG-IP Access Policy Manager (APM) ACL bypass Vulnerability (K75540265)
An attacker may be able to bypass APM's internal restrictions and retrieve static content that is hosted within APM by sending specifically crafted requests to an APM Virtual Server. CVE-2021-23016
Vulnerable Component: BIG-IP APM
Affected Versions:
16.0.0 - 16.0.1
15.1.0 - 15.1.2
14.1.0 - 14.1.4
13.1.0 - 13.1.3
12.1.0 - 12.1.6
11.6.1 - 11.6.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
This vulnerability may allow an attacker to retrieve static content hosted on the BIG-IP system that they would otherwise not be able to, allowing them to fingerprint a device more effectively. It does not allow any modification of data nor the exposure of any sensitive information or personally identifiable information (PII) in the standard, default, or recommended configurations.
- K75540265 -
support.f5.com/csp/article/K75540265
CVEs related to QID 376050
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K75540265 |
|