Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Njs CRITICAL 9.8
CVE-2022-25139

njs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled.

Fix: 0.7.2+
Fix from $2,300 2022-02-14
Njs CRITICAL 9.8
CVE-2021-46463

njs through 0.7.1, used in NGINX, was discovered to contain a control flow hijack caused by a Type Confusion vulnerability in njs_promise_perform_the…

Fix: after 0.7.1
Fix from $2,300 2022-02-14
Njs HIGH 7.5
CVE-2021-46462

njs through 0.7.1, used in NGINX, was discovered to contain a segmentation violation via njs_object_set_prototype in /src/njs_object.c.

Fix: after 0.7.1
Fix from $1,950 2022-02-14
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2022-23032

In all versions before 7.2.1.4, when proxy settings are configured in the network access resource of a BIG-IP APM system, connecting BIG-IP Edge Clie…

Fix: after 16.1.2
Fix from $1,600 2022-01-25
Big Ip Domain Name System HIGH 8.8
CVE-2022-23013

On BIG-IP DNS & GTM version 16.x before 16.1.0, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, a DOM-b…

Fix: 14.1.4.4 / 15.1.4+
Fix from $1,950 2022-01-25
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-23010

On BIG-IP versions 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, when a FastL4 …

Fix: 14.1.4.4 / 15.1.4.1+
Fix from $1,950 2022-01-25
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-23011

On certain hardware BIG-IP platforms, in version 15.1.x before 15.1.4 and 14.1.x before 14.1.3, virtual servers may stop responding while processing …

Fix: 14.1.3 / 15.1.4+
Fix from $1,950 2022-01-25
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-23012

On BIG-IP versions 15.1.x before 15.1.4.1 and 14.1.x before 14.1.4.5, when the HTTP/2 profile is configured on a virtual server, undisclosed requests…

Fix: 14.1.4.5 / 15.1.4.1+
Fix from $1,950 2022-01-25
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-23015

On BIG-IP versions 16.x before 16.1.0, 15.1.x before 15.1.4.1, and 14.1.2.6-14.1.4.4, when a Client SSL profile is configured on a virtual server wit…

Fix: 14.1.4.4 / 15.1.4.1+
Fix from $1,950 2022-01-25
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-23016

On versions 16.1.x before 16.1.2 and 15.1.x before 15.1.4.1, when BIG-IP SSL Forward Proxy with TLS 1.3 is configured on a virtual server, undisclose…

Fix: 15.1.4.1 / 16.1.2+
Fix from $1,950 2022-01-25
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-23017

On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when a virtual server is configured…

Fix: 14.1.4.5 / 15.1.4.1+
Fix from $1,950 2022-01-25
Big Ip Advanced Firewall Manager HIGH 7.5
CVE-2022-23018

On BIG-IP AFM version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and 13.1.x beginning in 13.1.3.4, when a virtual server i…

Fix: 13.1.4.1 / 14.1.4.5+
Fix from $1,950 2022-01-25
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-23019

On BIG-IP version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x and 12.1.x, when a message routing…

Fix: 14.1.4.4 / 15.1.4.1+
Fix from $1,950 2022-01-25
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-23020

On BIG-IP version 16.1.x before 16.1.2, when the 'Respond on Error' setting is enabled on the Request Logging profile and configured on a virtual ser…

Fix: 16.1.2+
Fix from $1,950 2022-01-25
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-23021

On BIG-IP version 16.1.x before 16.1.2, when any of the following configurations are configured on a virtual server, undisclosed requests can cause t…

Fix: 16.1.2+
Fix from $1,950 2022-01-25
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-23022

On BIG-IP version 16.1.x before 16.1.2, when an HTTP profile is configured on a virtual server, undisclosed requests can cause the Traffic Management…

Fix: 16.1.2+
Fix from $1,950 2022-01-25
Big Ip Advanced Firewall Manager HIGH 7.5
CVE-2022-23024

On BIG-IP AFM version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.2, and all versions of 13.1.x, when the IPsec application laye…

Fix: after 15.1.4
Fix from $1,950 2022-01-25
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-23025

On BIG-IP version 16.1.x before 16.1.1, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, when a SIP ALG profile is configure…

Fix: after 16.1.1
Fix from $1,950 2022-01-25
Big Iq Centralized Management HIGH 7.2
CVE-2022-23009

On BIG-IQ Centralized Management 8.x before 8.1.0, an authenticated administrative role user on a BIG-IQ managed BIG-IP device can access other BIG-I…

Mitigation only
Fix from $1,950 2022-01-25
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2022-23014

On versions 16.1.x before 16.1.2 and 15.1.x before 15.1.4.1, when BIG-IP APM portal access is configured on a virtual server, undisclosed requests ca…

Fix: 15.1.4.1 / 16.1.2+
Fix from $1,600 2022-01-25
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2022-23023

On BIG-IP version 16.1.x before 16.1.2.1, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, and BIG-IQ all version…

Fix: after 16.1.2
Fix from $1,600 2022-01-25
Nginx Controller Api Management MEDIUM 5.4
CVE-2022-23008

On NGINX Controller API Management versions 3.18.0-3.19.0, an authenticated attacker with access to the "user" or "admin" role can use undisclosed AP…

Fix: 3.19.1+
Fix from $1,600 2022-01-25
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2022-23027

On BIG-IP versions 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, 13.1.x beginning in 13.1.3.6, 12.1.5.3-12.1.6, and 11.6.5.2, when a FastL4 profile a…

Fix: after 15.1.3
Fix from $1,600 2022-01-25
Big Ip Advanced Firewall Manager MEDIUM 5.3
CVE-2022-23028

On BIG-IP AFM version 16.x before 16.1.0, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when global AFM SYN cookie protec…

Fix: after 15.1.4
Fix from $1,600 2022-01-25
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2022-23029

On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, when a FastL4 p…

Fix: after 15.1.4
Fix from $1,600 2022-01-25
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2022-23030

On version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when the BIG-IP Virtual Edition (VE) use…

Fix: after 16.1.1
Fix from $1,600 2022-01-25
Nginx Modsecurity Waf HIGH 7.5
CVE-2021-42717

ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in th…

Fix: 2.9.5 / 3.0.6+
Fix from $1,950 2021-12-07
Big Ip Access Policy Manager HIGH 7.5
CVE-2002-20001EPSS 23%

The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys,…

Fix: 16.1.4 / 17.1.0+
Fix from $1,950 2021-11-11
Big Ip Access Policy Manager MEDIUM 6.1
CVE-2021-23054

On version 16.x before 16.1.0, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, a reflected cross-site s…

Fix: 14.1.4.4 / 15.1.4+
Fix from $1,600 2021-09-27
Big Ip Advanced Web Application Firewall HIGH 8.8
CVE-2021-23029

On version 16.0.x before 16.0.1.2, insufficient permission checks may allow authenticated users with guest privileges to perform Server-Side Request …

Fix: 16.0.1.2+
Fix from $1,950 2021-09-14