CVE-2018-15324: Input Validation
Published Oct 31, 2018
·Updated
On BIG-IP APM 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, TMM may restart when processing a specially crafted request with APM portal access.
Affected Software
2 affected components
F5 BIG-IP Access Policy Manager>=13.0.0<=13.1.1.1
F5 BIG-IP Access Policy Manager>=14.0.0<=14.0.0.2
Event History
Oct 31, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-15324?
CVE-2018-15324 has a high severity due to potential service disruption caused by TMM restarts.
2
How do I fix CVE-2018-15324?
To fix CVE-2018-15324, upgrade F5 BIG-IP APM to a version higher than 14.0.0-14.0.0.2 or 13.1.1.1.
3
Which versions of BIG-IP APM are affected by CVE-2018-15324?
CVE-2018-15324 affects BIG-IP APM versions 14.0.0-14.0.0.2 and 13.0.0-13.1.1.1.
4
What can happen if CVE-2018-15324 is exploited?
Exploitation of CVE-2018-15324 may lead to TMM restarts, resulting in service interruptions.
5
Is there a workaround for CVE-2018-15324?
There is no specific workaround for CVE-2018-15324; the recommended action is to upgrade to a secure version.