CVE-2018-15327: High severity riverbed steelapp traffic manager vulnerability
In BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1 or Enterprise Manager 3.1.1, when authenticated administrative users run commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-15327?
CVE-2018-15327 is a vulnerability in BIG-IP and Enterprise Manager that allows authenticated administrative users to bypass command restrictions.
Which software versions are affected by CVE-2018-15327?
Versions 14.0.0-14.0.0.2 and 13.0.0-13.1.1.1 of BIG-IP, as well as version 3.1.1 of Enterprise Manager are affected by CVE-2018-15327.
What is the severity of CVE-2018-15327?
The severity of CVE-2018-15327 is rated as high with a CVSS score of 7.2.
How can I fix CVE-2018-15327?
To fix CVE-2018-15327, upgrade to a version above 14.0.0.2 or 13.1.1.1 for BIG-IP, and upgrade to a version above 3.1.1 for Enterprise Manager.
Where can I find more information about CVE-2018-15327?
You can find more information about CVE-2018-15327 on the F5 support website: https://support.f5.com/csp/article/K20222812