QID 379261
Date Published: 2024-01-22
QID 379261: F5 BIG-IP Apache Integer Overflow Vulnerability (K000137702)
CVE-2022-25147 - Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds of a buffer.
Affected Versions:
F5 BIG-IP version 17.1.0 - 17.1.1
F5 BIG-IP version 16.1.0 - 16.1.4
F5 BIG-IP version 15.1.0 - 15.1.10
F5 BIG-IP version 14.1.0 - 14.1.5
F5 BIG-IP version 13.1.0 - 13.1.5
QID Detection Logic (Authenticated):
This QID checks for vulnerable version of F5 BIG-IP by running the 'tmsh -q show /sys version' command.
This vulnerability may allow an attacker to overwrite memory beyond the intended buffer.
Workaround:
The vendor has suggested the following workarounds as temporary solution until the patches are introduced:
Block Configuration utility access through self IP addresses.
Block Configuration utility access through the management interface
- K000137702 -
my.f5.com/manage/s/article/K000137702
CVEs related to QID 379261
| Advisory ID | Software | Component | Link |
|---|