CVE-2018-15325: Medium severity riverbed steelapp traffic manager vulnerability
In BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, iControl and TMSH usage by authenticated users may leak a small amount of memory when executing commands
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2018-15325.
What is the title and description of the vulnerability?
The title of the vulnerability is 'In BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1 iControl and TMSH usage by authenticated users may leak...' and the description is 'In BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, iControl and TMSH usage by authenticated users may leak a small amount of memory when executing commands.'
What is the affected software?
The affected software includes F5 Big-ip Local Traffic Manager, F5 BIG-IP Advanced Firewall Manager, F5 Big-ip Application Acceleration Manager, F5 BIG-IP Analytics, F5 BIG-IP Access Policy Manager, F5 Big-ip Protocol Security Module, F5 Big-ip Domain Name System, F5 Big-ip Edge Gateway, F5 Big-ip Fraud Protection Service, F5 Big-ip Global Traffic Manager, F5 Big-ip Link Controller, F5 Big-ip Policy Enforcement Manager, and F5 Big-ip Webaccelerator.
What is the severity of CVE-2018-15325?
The severity of CVE-2018-15325 is medium (4.3).
How can I fix this vulnerability?
To fix this vulnerability, you need to upgrade your F5 BIG-IP software to versions 13.1.1.2, 14.0.0.3, 14.1.0.2, 15.0.0, or later.