CVE-2016-3687

Severity

40%

Complexity

49%

Confidentiality

81%

CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

Open redirect vulnerability in F5 BIG-IP APM 11.2.1, 11.4.x, 11.5.x, and 11.6.x before 11.6.0 HF6 and Edge Gateway 11.2.1, when using multi-domain single sign-on (SSO), allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a base64-encoded URL in the SSO_ORIG_URI parameter.

CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

CVSS 3.0 Base Score 5.3. CVSS Attack Vector: network. CVSS Attack Complexity: high. CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N).

CVSS 2.0 Base Score 4. CVSS Attack Vector: network. CVSS Attack Complexity: high. CVSS Vector: (AV:N/AC:H/Au:N/C:P/I:P/A:N).

Overview

Type

F5

First reported 8 years ago

2016-06-16 18:59:00

Last updated 8 years ago

2016-06-20 12:16:00

Affected Software

F5 Big-IP Access Policy Manager (APM) 11.2.1

11.2.1

F5 BIG-IP Access Policy Manager 11.4.0

11.4.0

F5 BIG-IP Access Policy Manager 11.4.1

11.4.1

F5 BIG-IP Access Policy Manager 11.5.0

11.5.0

F5 Big-IP Access Policy Manager (APM) 11.5.1

11.5.1

F5 BIG-IP Access Policy Manager 11.5.2

11.5.2

F5 BIG-IP Access Policy Manager 11.5.3

11.5.3

F5 Big-IP Access Policy Manager (APM) 11.5.4

11.5.4

F5 Big-IP Access Policy Manager (APM) 11.6.0

11.6.0

F5 BIG-IP IP Edge Gateway 11.2.1

11.2.1

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.