Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Big Ip Controller CRITICAL 9.8
CVE-2019-5021EPSS 6%

Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the re…

Patch available
Fix from $2,300 2019-05-08
Big Ip Access Policy Manager HIGH 7.5
CVE-2019-6619

On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, the Traffic Management Microkernel (TMM) may restart when a virtual server has an HTTP…

Fix: 12.1.4.1 / 13.1.1.5+
Fix from $1,950 2019-05-03
Big Ip Access Policy Manager HIGH 7.2
CVE-2019-6616

On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, administrative users with TMSH access can overwrite cr…

Fix: 11.5.9 / 11.6.4+
Fix from $1,950 2019-05-03
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2019-6614

On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, internal methods used to prevent arbitrary file overwrites in Appliance Mode were not …

Fix: 12.1.4.1 / 13.1.1.5+
Fix from $1,600 2019-05-03
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2019-6617

On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, a user with the Resource Administrator role is able to…

Fix: 11.5.9 / 11.6.4+
Fix from $1,600 2019-05-03
Big Ip Access Policy Manager HIGH 7.5
CVE-2019-6611

When BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8 are processing certain rare data sequences occurring …

Fix: 11.5.9 / 11.6.4+
Fix from $1,950 2019-05-03
Big Ip Access Policy Manager HIGH 7.5
CVE-2019-6612

On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, DNS query TCP connections that are aborted before rece…

Fix: 11.5.9 / 11.6.4+
Fix from $1,950 2019-05-03
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2019-6613

On BIG-IP 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, SNMP may expose sensitive configuration objects over insecure transmiss…

Fix: 11.5.9 / 11.6.4+
Fix from $1,600 2019-05-03
Big Ip Local Traffic Manager CRITICAL 9.8
CVE-2019-6609

Platform dependent weakness. This issue only impacts iSeries platforms. On these platforms, in BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge …

Fix: 12.1.4.1 / 13.1.1.4+
Fix from $2,300 2019-04-15
Big Ip Access Policy Manager HIGH 8.6
CVE-2019-6610

On BIG-IP versions 14.0.0-14.0.0.4, 13.0.0-13.1.1.1, 12.1.0-12.1.4, 11.6.0-11.6.3.4, and 11.5.1-11.5.8, the system is vulnerable to a denial of servi…

Fix: after 13.1.1
Fix from $1,950 2019-04-11
Big Ip Access Policy Manager HIGH 7.5
CVE-2019-6602

In BIG-IP 11.5.1-11.5.8 and 11.6.1-11.6.3, the Configuration Utility login page may not follow best security practices when handling a malicious requ…

Fix: after 11.6.3
Fix from $1,950 2019-03-28
Big Ip Access Policy Manager HIGH 7.5
CVE-2019-6603

In BIG-IP 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3, and 13.0.0-13.0.1, malformed TCP packets sent to a self IP address or a FastL4 virtual server …

Fix: after 13.0.1
Fix from $1,950 2019-03-28
Big Ip Access Policy Manager HIGH 7.5
CVE-2019-6605

On BIG-IP 11.5.1-11.5.8, 11.6.1-11.6.3, and 12.0.x, an undisclosed sequence of packets received by an SSL virtual server and processed by an associat…

Fix: 11.5.9 / 11.6.4+
Fix from $1,950 2019-03-28
Big Ip Access Policy Manager MEDIUM 6.8
CVE-2019-6604

On BIG-IP 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3.6, 13.0.0-13.1.1.1, and 14.0.0-14.0.0.2, under certain conditions, hardware systems with a High…

Fix: after 13.1.1
Fix from $1,600 2019-03-28
Big Ip Application Security Manager MEDIUM 6.8
CVE-2019-6607

On BIG-IP ASM 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3, 13.0.0-13.1.1.3, and 14.0.0-14.0.0.2, there is a stored cross-site scripting vulnerability…

Fix: after 14.0.0.2
Fix from $1,600 2019-03-28
Big Ip Access Policy Manager MEDIUM 5.9
CVE-2019-6608

On BIG-IP 11.5.1-11.6.3, 12.1.0-12.1.3, 13.0.0-13.1.1.1, and 14.0.0-14.0.0.2, under certain conditions, the snmpd daemon may leak memory on a multi-b…

Fix: after 14.0.0.2
Fix from $1,600 2019-03-28
Big Ip Access Policy Manager HIGH 7.5
CVE-2019-6596

In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, 12.1.0-12.1.3.6, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, when processing fragmented ClientHello messages in a …

Fix: after 13.1.1
Fix from $1,950 2019-03-13
Big Ip Local Traffic Manager HIGH 7.2
CVE-2019-6597

In BIG-IP 13.0.0-13.1.1.1, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8 or Enterprise Manager 3.1.1, when authenticated administrative users ru…

Fix: after 13.1.1.1
Fix from $1,950 2019-03-13
Big Ip Access Policy Manager MEDIUM 6.1
CVE-2019-6599

In BIG-IP 11.6.1-11.6.3.2 or 11.5.1-11.5.8, or Enterprise Manager 3.1.1, improper escaping of values in an undisclosed page of the configuration util…

Fix: after 11.6.3
Fix from $1,600 2019-03-13
Big Ip Local Traffic Manager MEDIUM 6.1
CVE-2019-6600

In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.3, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, when remote authentication is enabled for administrat…

Fix: after 14.0.0.2
Fix from $1,600 2019-03-13
Big Ip Application Acceleration Manager MEDIUM 5.5
CVE-2019-6601

In BIG-IP 13.0.0, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, the Application Acceleration Manager (AAM) wamd process used in processing of i…

Fix: after 12.1.3
Fix from $1,600 2019-03-13
Big Ip Access Policy Manager CRITICAL 9.1
CVE-2019-6592

On BIG-IP 14.1.0-14.1.0.1, TMM may restart and produce a core file when validating SSL certificates in client SSL or server SSL profiles.

Fix: after 14.1.0.1
Fix from $2,300 2019-02-26
Big Ip Access Policy Manager MEDIUM 6.1
CVE-2019-6595

Cross-site scripting (XSS) vulnerability in F5 BIG-IP Access Policy Manager (APM) 11.5.x and 11.6.x Admin Web UI.

Fix: after 11.6.3
Fix from $1,600 2019-02-26
Big Ip Access Policy Manager MEDIUM 5.9
CVE-2019-6593

On BIG-IP 11.5.1-11.5.4, 11.6.1, and 12.1.0, a virtual server configured with a Client SSL profile may be vulnerable to a chosen ciphertext attack ag…

Fix: after 11.5.4
Fix from $1,600 2019-02-26
Big Ip Access Policy Manager MEDIUM 5.9
CVE-2019-6594

On BIG-IP 11.5.1-11.6.3.2, 12.1.3.4-12.1.3.7, 13.0.0 HF1-13.1.1.1, and 14.0.0-14.0.0.2, Multi-Path TCP (MPTCP) does not protect against multiple zero…

Fix: after 14.0.0.2
Fix from $1,600 2019-02-26
Big Ip Local Traffic Manager MEDIUM 6.1
CVE-2019-6589

On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.3, 12.1.0-12.1.3.7, and 11.6.0-11.6.3.2, a reflected Cross Site Scripting (XSS) vulnerability is present in …

Fix: after 14.0.0.2
Fix from $1,600 2019-02-14
Nginx Unit CRITICAL 9.8
CVE-2019-7401

NGINX Unit before 1.7.1 might allow an attacker to cause a heap-based buffer overflow in the router process with a specially crafted request. This ma…

Fix: 1.7.1+
Fix from $2,300 2019-02-08
Big Ip Local Traffic Manager MEDIUM 5.9
CVE-2019-6590

On BIG-IP LTM 13.0.0 to 13.0.1 and 12.1.0 to 12.1.3.6, under certain conditions, the TMM may consume excessive resources when processing SSL Session …

Fix: after 13.0.1
Fix from $1,600 2019-02-05
Big Ip Access Policy Manager MEDIUM 5.4
CVE-2019-6591

On BIG-IP APM 14.0.0 to 14.0.0.4, 13.0.0 to 13.1.1.3 and 12.1.0 to 12.1.3.7, a reflected cross-site scripting (XSS) vulnerability exists in the resou…

Fix: after 14.0.0.4
Fix from $1,600 2019-02-05
Traffix Signaling Delivery Controller HIGH 7.5
CVE-2018-20657

The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leadin…

Fix: after 5.1.0
Fix from $1,950 2019-01-02