Skip to main content

Vendor/product archive

f5 / big-ip_policy_enforcement_manager CVEs

Beta · best-effort

522 CVEs tagged to f5 / big-ip_policy_enforcement_manager32 Critical, 304 High, 179 Medium, 7 Low, 0 Unrated.

CVE-2016-9251

Published May 9, 2017

In F5 BIG-IP 12.0.0 through 12.1.2, an authenticated attacker may be able to cause an escalation of privileges through a crafted iControl REST connection.

CVSS 8.8 · High

CVE-2016-7468

Published Mar 23, 2017

An unauthenticated remote attacker may be able to disrupt services on F5 BIG-IP 11.4.1 - 11.5.4 devices with maliciously crafted network traffic. This vulnerability affects virtua…

CVSS 5.9 · Medium

CVE-2016-9245

Published Mar 7, 2017

In F5 BIG-IP systems 12.1.0 - 12.1.2, malicious requests made to virtual servers with an HTTP profile can cause the TMM to restart. The issue is exposed with BIG-IP APM profiles,…

CVSS 5.9 · Medium

CVE-2016-6249

Published Feb 20, 2017

F5 BIG-IP 12.0.0 and 11.5.0 - 11.6.1 REST requests which timeout during user account authentication may log sensitive attributes such as passwords in plaintext to /var/log/restjav…

CVSS 5.3 · Medium

CVE-2016-9244

Published Feb 9, 2017

A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized memory. A remote atta…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2016-9249

Published Jan 31, 2017

An undisclosed traffic pattern received by a BIG-IP Virtual Server with TCP Fast Open enabled may cause the Traffic Management Microkernel (TMM) to restart, resulting in a Denial-…

CVSS 7.5 · High

CVE-2016-9247

Published Jan 10, 2017

Under certain conditions for BIG-IP systems using a virtual server with an associated FastL4 profile and TCP analytics profile, a specific sequence of packets may cause the Traffi…

CVSS 5.9 · Medium

CVE-2016-5024

Published Jan 3, 2017

Virtual servers in F5 BIG-IP systems 11.6.1 before 11.6.1 HF1 and 12.1.x before 12.1.2, when configured to parse RADIUS messages via an iRule, allow remote attackers to cause a de…

CVSS 5.9 · Medium

CVE-2016-5700

Published Oct 3, 2016

Virtual servers in F5 BIG-IP systems 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0 before HF4, and 12.1.0 before HF2,…

CVSS 9.8 · Critical

CVE-2016-4545

Published Jun 7, 2016

Virtual servers in F5 BIG-IP 11.5.4, when SSL profiles are enabled, allow remote attackers to cause a denial of service (resource consumption and Traffic Management Microkernel re…

CVSS 7.5 · High

CVE-2015-8240

Published Apr 11, 2016

The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and BIG-IP PEM before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x…

CVSS 7.5 · High
Showing 476-500 of 522 CVEsPage 20 of 21