CVE-2015-8022

Severity

85%

Complexity

68%

Confidentiality

165%

The Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, and Link Controller 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP AAM 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP AFM and PEM 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP Edge Gateway, WebAccelerator, and WOM 11.x before 11.2.1 HF16 and 11.3.0; and BIG-IP PSM 11.x before 11.2.1 HF16, 11.3.x, and 11.4.x before 11.4.1 HF10 allows remote authenticated users with certain permissions to gain privileges by leveraging an Access Policy Manager customization configuration section that allows file uploads.

The Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, and Link Controller 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP AAM 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP AFM and PEM 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP Edge Gateway, WebAccelerator, and WOM 11.x before 11.2.1 HF16 and 11.3.0; and BIG-IP PSM 11.x before 11.2.1 HF16, 11.3.x, and 11.4.x before 11.4.1 HF10 allows remote authenticated users with certain permissions to gain privileges by leveraging an Access Policy Manager customization configuration section that allows file uploads.

CVSS 3.0 Base Score 7.5. CVSS Attack Vector: network. CVSS Attack Complexity: high. CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS 2.0 Base Score 8.5. CVSS Attack Vector: network. CVSS Attack Complexity: medium. CVSS Vector: (AV:N/AC:M/Au:S/C:C/I:C/A:C).

Overview

Type

F5

First reported 8 years ago

2016-08-19 21:59:00

Last updated 5 years ago

2019-06-06 15:11:00

Affected Software

F5 BIG-IP Global Traffic Manager (GTM) 11.0.0

11.0.0

F5 BIG-IP Global Traffic Manager (GTM) 11.1.0

11.1.0

F5 BIG-IP Global Traffic Manager (GTM) 11.2.0

11.2.0

F5 Networks BIGIP Global Traffic Manager 11.2.1

11.2.1

F5 BIG-IP Global Traffic Manager 11.3.0

11.3.0

F5 BIG-IP Global Traffic Manager 11.4.0

11.4.0

F5 BIG-IP Global Traffic Manager 11.4.1

11.4.1

F5 BIG-IP Global Traffic Manager 11.5.0

11.5.0

F5 Networks BIGIP Global Traffic Manager 11.5.1

11.5.1

F5 BIG-IP Global Traffic Manager 11.5.2

11.5.2

F5 BIG-IP Global Traffic Manager 11.5.3

11.5.3

F5 BIG-IP Global Traffic Manager 11.6.0

11.6.0

F5 BIG-IP Local Traffic Manager (LTM) 11.0.0

11.0.0

F5 BIG-IP Local Traffic Manager (LTM) 11.1.0

11.1.0

F5 BIG-IP Local Traffic Manager (LTM)11.2.0

11.2.0

F5 Networks BIGIP Local Traffic Manager (LTM) 11.2.1

11.2.1

F5 BIG-IP Local Traffic Manager 11.3.0

11.3.0

F5 BIG-IP Local Traffic Manager 11.4.0

11.4.0

F5 BIG-IP Local Traffic Manager 11.4.1

11.4.1

F5 BIG-IP Local Traffic Manager 11.5.0

11.5.0

F5 Networks BIGIP Local Traffic Manager (LTM) 11.5.1

11.5.1

F5 BIG-IP Local Traffic Manager 11.5.2

11.5.2

F5 BIG-IP Local Traffic Manager 11.5.3

11.5.3

F5 BIG-IP Local Traffic Manager 11.6.0

11.6.0

F5 BIG-IP WebAccelerator 11.0.0

11.0.0

F5 BIG-IP WebAccelerator 11.1.0

11.1.0

F5 BIG-IP WebAccelerator 11.2.0

11.2.0

F5 Networks BIGIP WebAccelerator 11.2.1

11.2.1

F5 Networks BIGIP WebAccelerator 11.3.0

11.3.0

F5 Networks BIGIP Policy Enforcement Manager 11.3.0

11.3.0

F5 BIG-IP Policy Enforcement Manager 11.4.0

11.4.0

F5 BIG-IP Policy Enforcement Manager 11.4.1

11.4.1

F5 BIG-IP Policy Enforcement Manager 11.5.0

11.5.0

F5 Networks BIGIP Policy Enforcement Manager 11.5.1

11.5.1

F5 BIG-IP Policy Enforcement Manager 11.5.2

11.5.2

F5 Networks BIG-IP Policy Enforcement Manager 11.5.3

11.5.3

F5 BIG-IP Policy Enforcement Manager 11.6.0

11.6.0

F5 BIG-IP Advanced Firewall Manager 11.3.0

11.3.0

F5 BIG-IP Advanced Firewall Manager 11.4.0

11.4.0

F5 BIG-IP Advanced Firewall Manager 11.4.1

11.4.1

F5 BIG-IP Advanced Firewall Manager 11.5.0

11.5.0

F5 Networks BIGIP Advanced Firewall Manager 11.5.1

11.5.1

F5 BIG-IP Advanced Firewall Manager 11.5.2

11.5.2

F5 BIG-IP Advanced Firewall Manager 11.5.3

11.5.3

F5 BIG-IP Advanced Firewall Manager 11.6.0

11.6.0

F5 Big-IP Access Policy Manager (APM) 11.0.0

11.0.0

F5 Big-IP Access Policy Manager (APM) 11.1.0

11.1.0

F5 Big-IP Access Policy Manager (APM) 11.2.0

11.2.0

F5 Big-IP Access Policy Manager (APM) 11.2.1

11.2.1

F5 Big-IP Access Policy Manager (APM) 11.3.0

11.3.0

F5 BIG-IP Access Policy Manager 11.4.0

11.4.0

F5 BIG-IP Access Policy Manager 11.4.1

11.4.1

F5 BIG-IP Access Policy Manager 11.5.0

11.5.0

F5 Big-IP Access Policy Manager (APM) 11.5.1

11.5.1

F5 BIG-IP Access Policy Manager 11.5.2

11.5.2

F5 BIG-IP Access Policy Manager 11.5.3

11.5.3

F5 Big-IP Access Policy Manager (APM) 11.6.0

11.6.0

F5 BIG-IP Analytics 11.0.0

11.0.0

F5 BIG-IP Analytics 11.1.0

11.1.0

F5 BIG-IP Analytics 11.2.0

11.2.0

F5 Networks BIGIP Analytics 11.2.1

11.2.1

F5 BIG-IP Analytics 11.3.0

11.3.0

F5 BIG-IP Analytics 11.4.0

11.4.0

F5 BIG-IP Analytics 11.4.1

11.4.1

F5 BIG-IP Analytics 11.5.0

11.5.0

F5 Networks BIGIP Analytics 11.5.1

11.5.1

F5 BIG-IP Analytics 11.5.2

11.5.2

F5 BIG-IP Analytics 11.5.3

11.5.3

F5 BIG-IP Analytics 11.6.0

11.6.0

F5 BIG-IP Wan Optimization Manager (WOM) 11.0.0

11.0.0

F5 BIG-IP Wan Optimization Manager (WOM) 11.1.0

11.1.0

F5 BIG-IP WAN Optimization Manager (WOM) 11.2.0

11.2.0

F5 Networks BIGIP WAN Optimization Manager 11.2.1

11.2.1

F5 Networks BIGIP WAN Optimization Manager 11.3.0

11.3.0

F5 BIG-IP Link Controller 11.0.0

11.0.0

F5 BIG-IP Link Controller 11.1.0

11.1.0

F5 BIG-IP Link Controller 11.2.0

11.2.0

F5 Networks BIGIP Link Controller 11.2.1

11.2.1

F5 BIG-IP Link Controller 11.3.0

11.3.0

F5 BIG-IP Link Controller 11.4.0

11.4.0

F5 BIG-IP Link Controller 11.4.1

11.4.1

F5 BIG-IP Link Controller 11.5.0

11.5.0

F5 Networks BIGIP Link Controller 11.5.1

11.5.1

F5 BIG-IP Link Controller 11.5.2

11.5.2

F5 BIG-IP Link Controller 11.5.3

11.5.3

F5 BIG-IP Link Controller 11.6.0

11.6.0

F5 BIG-IP IP Edge Gateway 11.0.0

11.0.0

F5 BIG-IP Edge Gateway 11.1.0

11.1.0

F5 BIG-IP Edge Gateway 11.2.0

11.2.0

F5 BIG-IP IP Edge Gateway 11.2.1

11.2.1

F5 BIG-IP IP Edge Gateway 11.3.0

11.3.0

F5 BIG-IP Application Security Manager (PSM) 11.0.0

11.0.0

F5 BIG-IP Application Security Manager (PSM) 11.1.0

11.1.0

F5 BIG-IP Application Security Manager (ASM) 11.2.0

11.2.0

F5 Networks BIG-IP Application Security Manager 11.2.1

11.2.1

F5 BIG-IP Application Security Manager 11.3.0

11.3.0

F5 BIG-IP Application Security Manager 11.4.0

11.4.0

F5 BIG-IP Application Security Manager 11.4.1

11.4.1

F5 BIG-IP Application Security Manager 11.5.0

11.5.0

F5 Networks BIG-IP Application Security Manager 11.5.1

11.5.1

F5 BIG-IP Application Security Manager 11.5.2

11.5.2

F5 BIG-IP Application Security Manager 11.5.3

11.5.3

F5 BIG-IP Application Security Manager 11.6.0

11.6.0

F5 Networks BIGIP Application Acceleration Manager 11.4.0

11.4.0

F5 BIG-IP Application Acceleration Manager 11.4.1

11.4.1

F5 BIG-IP Application Acceleration Manager 11.5.0

11.5.0

F5 Networks BIGIP Application Acceleration Manager 11.5.1

11.5.1

F5 BIG-IP Application Acceleration Manager 11.5.2

11.5.2

F5 BIG-IP Application Acceleration Manager 11.5.3

11.5.3

F5 BIG-IP Application Acceleration Manager 11.6.0

11.6.0

F5 Big-IP WebSafe 11.6.0

11.6.0

F5 BIG-IP Protocol Security Module (PSM) 11.0.0

11.0.0

F5 BIG-IP Protocol Security Module (PSM) 11.1.0

11.1.0

F5 BIG-IP Protocol Security Module (PSM) 11.2.0

11.2.0

F5 Networks BIGIP Protocol Security Module 11.2.1

11.2.1

F5 BIG-IP Protocol Security Module (PSM) 11.3.0

11.3.0

F5 BIG-IP Protocol Security Module (PSM) 11.4.0

11.4.0

F5 Networks BIGIP Protocol Security Module 11.4.1

11.4.1

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.