First published: Mon Mar 16 2009(Updated: )
The management interface in F5 BIG-IP 9.4.3 allows remote authenticated users with Resource Manager privileges to inject arbitrary Perl code via unspecified configuration settings related to Perl EP3 with templates, probably triggering static code injection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
F5 TMOS | =9.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-6474 is considered to have a high severity level due to the potential for arbitrary code execution.
To mitigate CVE-2008-6474, it is recommended to upgrade to a version of F5 BIG-IP that is not affected, such as later versions than 9.4.3.
CVE-2008-6474 affects remote authenticated users of F5 BIG-IP 9.4.3 with Resource Manager privileges.
CVE-2008-6474 allows attackers to inject arbitrary Perl code, which could lead to unauthorized access and control over the affected system.
Currently, there are no specific workarounds for CVE-2008-6474 other than upgrading to a secure version.