CVE-2015-8021: Medium severity f5 access policy manager vulnerability
Incomplete blacklist vulnerability in the Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, Link Controller, and PSM 11.x before 11.2.1 HF11, 11.3.x, 11.4.0 before HF8, and 11.4.1 before HF6; BIG-IP AAM 11.4.0 before HF8 and 11.4.1 before HF6; BIG-IP AFM and PEM 11.3.x, 11.4.0 before HF8, and 11.4.1 before HF6; and BIG-IP Edge Gateway, WebAccelerator, and WOM 11.x before 11.2.1 HF11 and 11.3.0 allows remote authenticated users to upload files via uploadImage.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8021?
CVE-2015-8021 has a medium severity rating indicating a potential risk of exploitation.
How do I fix CVE-2015-8021?
To mitigate the effects of CVE-2015-8021, it is recommended to update to the patched versions provided by F5.
What systems are affected by CVE-2015-8021?
CVE-2015-8021 affects various versions of F5 BIG-IP including LTM, APM, ASM, GTM, and others prior to specific HF releases.
Can CVE-2015-8021 lead to unauthorized access?
Yes, CVE-2015-8021 can potentially allow unauthorized access due to incomplete input validation.
Is there a workaround for CVE-2015-8021?
Implementing proper configurations and access controls may help mitigate some risks associated with CVE-2015-8021.