First published: Wed Oct 31 2018(Updated: )
On BIG-IP APM 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, TMM may restart when processing a specially crafted request with APM portal access.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Access Policy Manager | >=13.0.0<=13.1.1.1 | |
F5 Access Policy Manager | >=14.0.0<=14.0.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15324 has a high severity due to potential service disruption caused by TMM restarts.
To fix CVE-2018-15324, upgrade F5 BIG-IP APM to a version higher than 14.0.0-14.0.0.2 or 13.1.1.1.
CVE-2018-15324 affects BIG-IP APM versions 14.0.0-14.0.0.2 and 13.0.0-13.1.1.1.
Exploitation of CVE-2018-15324 may lead to TMM restarts, resulting in service interruptions.
There is no specific workaround for CVE-2018-15324; the recommended action is to upgrade to a secure version.