Skip to main content

Vendor/product archive

f5 / big-ip_application_acceleration_manager CVEs

Beta · best-effort

518 CVEs tagged to f5 / big-ip_application_acceleration_manager30 Critical, 304 High, 177 Medium, 7 Low, 0 Unrated.

CVE-2017-6133

Published Dec 21, 2017

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM and WebSafe software version 13.0.0 and 12.1.0 - 12.1.2, undisclosed HTTP requests may cause a denial of…

CVSS 7.5 · High

CVE-2017-6132

Published Dec 21, 2017

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 13.0.0, 12.0.0 to 12.1.2, 11.6.0 to 11.6.1 and 11.5.0 - 11.5.4, an und…

CVSS 7.5 · High

CVE-2017-6163

Published Oct 27, 2017

In F5 BIG-IP LTM, AAM, AFM, APM, ASM, Link Controller, PEM, PSM software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1, 11.4.0 to 11.5.4, when a virtual server uses the standard conf…

CVSS 5.9 · Medium

CVE-2017-6162

Published Oct 27, 2017

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1, 11.4.0 to 11.5.4, 11.2.…

CVSS 5.9 · Medium

CVE-2017-6161

Published Oct 27, 2017

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, WebAccelerator software version 12.0.0 - 12.1.2, 11.6.0 - 11.6.1, 11.4.0 - 11.5.4, 1…

CVSS 5.3 · Medium

CVE-2017-6159

Published Oct 27, 2017

F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1 are vulnerable to a denial of service att…

CVSS 5.9 · Medium

CVE-2017-6157

Published Oct 27, 2017

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 12.0.0 to 12.1.1, 11.6.0 to 11.6.1, 11.5.0 - 11.5.4, virtual servers w…

CVSS 8.1 · High

CVE-2017-0303

Published Oct 27, 2017

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 13.0.0, 12.0.0 to 12.1.2 and 11.5.1 to 11.6.1, under limited circumsta…

CVSS 7.5 · High

CVE-2017-6145

Published Oct 20, 2017

iControl REST in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe 12.0.0 through 12.1.2 and 13.0.0 includes a service to convert authorization…

CVSS 7.3 · High

CVE-2017-6141

Published Oct 20, 2017

In F5 BIG-IP LTM, AAM, AFM, APM, ASM, Link Controller, PEM, and WebSafe 12.1.0 through 12.1.2, certain values in a TLS abbreviated handshake when using a client SSL profile with t…

CVSS 5.9 · Medium

CVE-2017-6147

Published Sep 18, 2017

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe 12.1.2-HF1 and 13.0.0, an undisclosed type of responses may cause TMM to restart, causing a…

CVSS 5.9 · Medium

CVE-2017-6131

Published May 23, 2017

In some circumstances, an F5 BIG-IP version 12.0.0 to 12.1.2 and 13.0.0 Azure cloud instance may contain a default administrative password which could be used to remotely log into…

CVSS 9.8 · Critical

CVE-2016-7476

Published May 11, 2017

The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, AAM, AFM, APM, ASM, GTM, Link Controller, PEM, PSM, and WebSafe 11.6.0 before 11.6.0 HF6, 11.5.0 before 11.5.3 HF2, and…

CVSS 7.5 · High

CVE-2017-6137

Published May 9, 2017

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, PSM, WebAccelerator, and WebSafe 11.6.1 HF1, 12.0.0 HF3, 12.0.0 HF4, and 12.1.0 thro…

CVSS 5.9 · Medium

CVE-2016-9256

Published May 9, 2017

In F5 BIG-IP 12.1.0 through 12.1.2, permissions enforced by iControl can lag behind the actual permissions assigned to a user if the role_map is not reloaded between the time the…

CVSS 7.5 · High

CVE-2016-9253

Published May 9, 2017

In F5 BIG-IP 12.1.0 through 12.1.2, specific websocket traffic patterns may cause a disruption of service for virtual servers configured to use the websocket profile.

CVSS 7.5 · High

CVE-2016-9251

Published May 9, 2017

In F5 BIG-IP 12.0.0 through 12.1.2, an authenticated attacker may be able to cause an escalation of privileges through a crafted iControl REST connection.

CVSS 8.8 · High
Showing 451-475 of 518 CVEsPage 19 of 21