QID 378096
Date Published: 2023-03-22
QID 378096: F5 BIG-IP Access Policy Manager (APM) Virtual Server Vulnerability CVE-2023-22418 (K95503300)
An open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy. This vulnerability allows an unauthenticated malicious attacker to build an open redirect URI. (CVE-2023-22418).
Vulnerable Component: BIG-IP APM
Affected Versions:
17.0.0
16.1.0 - 16.1.3
15.1.0 - 15.1.6
14.1.0 - 14.1.5
13.1.0 - 13.1.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
An unauthenticated attacker can create an open redirect URI with a specially crafted value and trick BIG-IP APM users into visiting the crafted URI. Victims may be redirected to a malicious website by following the misleading URI.
Solution
For more information about patch details please refer to K95503300
Vendor References
- K95503300 -
my.f5.com/manage/s/article/K95503300
CVEs related to QID 378096
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K95503300 |
|