First published: Mon Nov 17 2014(Updated: )
Multiple directory traversal vulnerabilities in F5 BIG-IP before 10.2.2 allow local users with the "Resource Administrator" or "Administrator" role to enumerate and delete arbitrary files via a .. (dot dot) in the name parameter to (1) tmui/Control/jspmap/tmui/system/archive/properties.jsp or (2) tmui/Control/form.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Riverbed SteelApp Traffic Manager | <=10.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8727 is classified as a medium severity vulnerability due to its potential for unauthorized access to sensitive files.
To fix CVE-2014-8727, upgrade F5 BIG-IP to version 10.2.2 or later, where the vulnerability has been addressed.
CVE-2014-8727 affects local users with the Resource Administrator or Administrator role on F5 BIG-IP versions prior to 10.2.2.
Exploiting CVE-2014-8727 allows attackers to enumerate and delete arbitrary files, potentially leading to data loss or service disruption.
F5 BIG-IP versions up to 10.2.1 are vulnerable to CVE-2014-8727 and should be updated to a secure version.