Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.4 CVE-2020-5913 In versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, the BIG-IP Client or Server SSL profile ignores … Big Ip Access Policy Manager 11.6.5 / 12.1.5.2+ Fix from $1,9502020-08-26 MEDIUM 6.8 CVE-2020-5916 In BIG-IP versions 15.1.0-15.1.0.4 and 15.0.0-15.0.1.3 the Certificate Administrator user role and higher privileged roles can perform arbitrary file… Big Ip Access Policy Manager 15.0.1.4 / 15.1.0.5+ Fix from $1,6002020-08-26 MEDIUM 6.1 CVE-2020-5915 In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, an undisclosed TMUI page… Big Ip Access Policy Manager 11.6.5.2 / 12.1.5.2+ Fix from $1,6002020-08-26 MEDIUM 5.9 CVE-2020-5917 In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2 and BIG-IQ versions 5.2.0… Big Ip Access Policy Manager 12.1.5.2 / 14.1.2.4+ Fix from $1,6002020-08-26 MEDIUM 5.4 CVE-2020-5923 In BIG-IP versions 15.0.0-15.1.0.4, 14.1.0-14.1.2.6, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1 and BIG-IQ versions 5.4.0-7.0.0, Self-IP p… Big Ip Access Policy Manager 11.6.5.2 / 12.1.5.2+ Fix from $1,6002020-08-26 MEDIUM 5.3 CVE-2020-5924 In BIG-IP APM versions 12.1.0-12.1.5.1 and 11.6.1-11.6.5.2, RADIUS authentication leaks memory when the username for authentication is not set. Big Ip Access Policy Manager 12.1.5.2+ Fix from $1,6002020-08-26 HIGH 7.1 CVE-2020-5912 In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the restjavad process's … Big Ip Access Policy Manager 11.6.5.2 / 12.1.5.2+ Fix from $1,9502020-08-26 MEDIUM 5.5 CVE-2020-24348 njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_json_stringify_iterator in njs_json.c. Njs after 0.4.3 Fix from $1,6002020-08-13 MEDIUM 5.5 CVE-2020-24349 njs through 0.4.3, used in NGINX, allows control-flow hijack in njs_value_property in njs_value.c. NOTE: the vendor considers the issue to be "fluff"… Njs after 0.4.3 Fix from $1,6002020-08-13 HIGH 7.8 CVE-2020-24346 njs through 0.4.3, used in NGINX, has a use-after-free in njs_json_parse_iterator_call in njs_json.c. Njs after 0.4.3 Fix from $1,9502020-08-13 MEDIUM 5.5 CVE-2020-24347 njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_lvlhsh_level_find in njs_lvlhsh.c. Njs after 0.4.3 Fix from $1,6002020-08-13 HIGH 7.5 CVE-2020-5910 In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do no… Nginx Controller after 3.5.0 Fix from $1,9502020-07-02 HIGH 7.3 CVE-2020-5911 In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packages from an HTTP URL On Debian… Nginx Controller after 3.5.0 Fix from $1,9502020-07-02 MEDIUM 5.4 CVE-2020-5909 In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent inst… Nginx Controller after 3.5.0 Fix from $1,6002020-07-02 CRITICAL 9.8 CVE-2020-5902 KEVEPSS 100% In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TM… Big Ip Access Policy Manager 11.6.5.2 / 12.1.5.2+ Fix from $2,3002020-07-01 CRITICAL 9.6 CVE-2020-5901 In NGINX Controller 3.3.0-3.4.0, undisclosed API endpoints may allow for a reflected Cross Site Scripting (XSS) attack. If the victim user is logged … Nginx Controller after 3.4.0 Fix from $2,3002020-07-01 HIGH 8.8 CVE-2020-5904 In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a cross-site request forgery (CSRF) vulnerability in the Traff… Big Ip Access Policy Manager after 15.1.0.3 Fix from $1,9502020-07-01 HIGH 8.1 CVE-2020-5906 In versions 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, the BIG-IP system does not properly enforce the access controls for the scp.blackl… Big Ip Access Policy Manager after 13.1.3 Fix from $1,9502020-07-01 HIGH 7.8 CVE-2020-5899 In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which al… Nginx Controller after 3.4.0 Fix from $1,9502020-07-01 HIGH 7.2 CVE-2020-5907 In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, an authorized user provided with access o… Big Ip Access Policy Manager after 15.1.0 Fix from $1,9502020-07-01 MEDIUM 6.1 CVE-2020-5903 In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a Cross-Site Scripting (XSS) vulnerability exists in an undisc… Big Ip Access Policy Manager after 15.1.0 Fix from $1,6002020-07-01 MEDIUM 5.5 CVE-2020-5908 In versions bundled with BIG-IP APM 12.1.0-12.1.5 and 11.6.1-11.6.5.2, Edge Client for Linux exposes full session ID in the local log files. Big Ip Access Policy Manager after 12.1.5 Fix from $1,6002020-07-01 HIGH 8.8 CVE-2020-5900 In versions 3.0.0-3.4.0, 2.0.0-2.9.0, and 1.0.1, there is insufficient cross-site request forgery (CSRF) protections for the NGINX Controller user in… Nginx Controller after 3.4.0 Fix from $1,9502020-07-01 HIGH 8.8 CVE-2020-5897 In versions 7.1.5-7.1.9, there is use-after-free memory vulnerability in the BIG-IP Edge Client Windows ActiveX component. Big Ip Access Policy Manager after 15.1.0.3 Fix from $1,9502020-05-12 HIGH 7.8 CVE-2020-5896 On versions 7.1.5-7.1.9, the BIG-IP Edge Client's Windows Installer Service's temporary folder has weak file and folder permissions. Big Ip Access Policy Manager after 15.1.0.3 Fix from $1,9502020-05-12 MEDIUM 5.5 CVE-2020-5898 In versions 7.1.5-7.1.9, BIG-IP Edge Client Windows Stonewall driver does not sanitize the pointer received from the userland. A local user on the Wi… Big Ip Access Policy Manager after 15.1.0.3 Fix from $1,6002020-05-12 HIGH 8.1 CVE-2020-5894 On versions 3.0.0-3.3.0, the NGINX Controller webserver does not invalidate the server-side session token after users log out. Nginx Controller after 3.3.0 Fix from $1,9502020-05-07 HIGH 7.8 CVE-2020-5895 On NGINX Controller versions 3.1.0-3.3.0, AVRD uses world-readable and world-writable permissions on its socket, which allows processes or users on t… Nginx Controller 3.4.0+ Fix from $1,9502020-05-07 MEDIUM 6.7 CVE-2020-5892 In versions 7.1.5-7.1.8, the BIG-IP Edge Client components in BIG-IP APM, Edge Gateway, and FirePass legacy allow attackers to obtain the full sessio… Big Ip Access Policy Manager after 15.1.0 Fix from $1,6002020-04-30 MEDIUM 5.5 CVE-2020-5890 On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1 and BIG-IQ 5.2.0-7.1.0, when creating a QKView, credentials for bindin… Big Iq Centralized Management 14.1.2.4 / 15.1.0.2+ Fix from $1,6002020-04-30