First published: Wed Jul 12 2017(Updated: )
iControl REST in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe 12.0.0 through 12.1.2 and 13.0.0 includes a service to convert authorization BIGIPAuthCookie cookies to X-F5-Auth-Token tokens. This service does not properly re-validate cookies when making that conversion, allowing once-valid but now expired cookies to be converted to valid tokens.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP Access Policy Manager | =12.1.0 | |
F5 BIG-IP Access Policy Manager | =12.1.1 | |
F5 BIG-IP Access Policy Manager | =12.1.2 | |
F5 BIG-IP Access Policy Manager | =13.0.0 | |
F5 BIG-IP Advanced Firewall Manager | =12.1.0 | |
F5 BIG-IP Advanced Firewall Manager | =12.1.1 | |
F5 BIG-IP Advanced Firewall Manager | =12.1.2 | |
F5 BIG-IP Advanced Firewall Manager | =13.0.0 | |
F5 BIG-IP Analytics | =12.1.0 | |
F5 BIG-IP Analytics | =12.1.1 | |
F5 BIG-IP Analytics | =12.1.2 | |
F5 BIG-IP Analytics | =13.0.0 | |
f5 big-ip application acceleration manager | =12.1.0 | |
f5 big-ip application acceleration manager | =12.1.1 | |
f5 big-ip application acceleration manager | =12.1.2 | |
f5 big-ip application acceleration manager | =13.0.0 | |
F5 BIG-IP Application Security Manager | =12.1.0 | |
F5 BIG-IP Application Security Manager | =12.1.1 | |
F5 BIG-IP Application Security Manager | =12.1.2 | |
F5 BIG-IP Application Security Manager | =13.0.0 | |
f5 big-ip domain name system | =12.1.0 | |
f5 big-ip domain name system | =12.1.1 | |
f5 big-ip domain name system | =12.1.2 | |
f5 big-ip domain name system | =13.0.0 | |
f5 big-ip link controller | =12.1.0 | |
f5 big-ip link controller | =12.1.1 | |
f5 big-ip link controller | =12.1.2 | |
f5 big-ip link controller | =13.0.0 | |
F5 BIG-IP Local Traffic Manager | =12.1.0 | |
F5 BIG-IP Local Traffic Manager | =12.1.1 | |
F5 BIG-IP Local Traffic Manager | =12.1.2 | |
F5 BIG-IP Local Traffic Manager | =13.0.0 | |
F5 BIG-IP Policy Enforcement Manager | =12.1.0 | |
F5 BIG-IP Policy Enforcement Manager | =12.1.1 | |
F5 BIG-IP Policy Enforcement Manager | =12.1.2 | |
F5 BIG-IP Policy Enforcement Manager | =13.0.0 | |
F5 WebSafe | =12.1.0 | |
F5 WebSafe | =12.1.1 | |
F5 WebSafe | =12.1.2 | |
F5 WebSafe | =13.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6145 has been assigned a CVSS score that indicates it is a medium severity vulnerability.
To fix CVE-2017-6145, you should upgrade to a patched version of the affected F5 BIG-IP software.
CVE-2017-6145 affects F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe versions 12.0.0 through 12.1.2 and 13.0.0.
CVE-2017-6145 involves improper cookie validation in the iControl REST API of multiple F5 BIG-IP products that could be exploited to impersonate users.
While upgrading to a secure version is recommended, temporary measures may include restricting access to the affected REST API services.