QID 378984
QID 378984: F5 BIG-IP SQL Injection Vulnerability (K000137365)
An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility.
This vulnerability may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands. There is no data plane exposure; this is a control plane issue only.
Vulnerable Component: BIG-IP All Modules
Affected Versions:
Prior to 17.1.0.
16.1.0 - 16.1.4
15.1.0 - 15.1.10
14.1.0 - 14.1.5
13.1.0 - 13.1.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
Successful exploit may allow an authenticated attacker to execute arbitrary system commands.
Solution
The vendor has released patch, for more information please visit: K000137365
Vendor References
- K000137365 -
my.f5.com/manage/s/article/K000137365
CVEs related to QID 378984
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K000137365 |
|