First published: Fri Oct 19 2018(Updated: )
In F5 BIG-IP APM 13.0.0-13.1.1.1, APM Client 7.1.5-7.1.6, and/or Edge Client 7101-7160, the BIG-IP APM Edge Client component loads the policy library with user permission and bypassing the endpoint checks.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Big-ip Access Policy Manager | >=13.0.0<=13.1.1.1 | |
F5 Big-ip Access Policy Manager Client | >=7.1.5<=7.1.6 | |
F5 Big-ip Edge Client | >=7101<=7160 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-15316.
The severity of CVE-2018-15316 is medium (5.5).
The F5 Big-ip Access Policy Manager, F5 Big-ip Access Policy Manager Client, and F5 Big-ip Edge Client are affected by CVE-2018-15316.
CVE-2018-15316 allows the BIG-IP APM Edge Client to load the policy library with user permission and bypass endpoint checks.
Yes, you can find additional information about CVE-2018-15316 at the following references: [1] http://www.securityfocus.com/bid/105731 [2] http://www.securitytracker.com/id/1041936 [3] https://support.f5.com/csp/article/K51220077