CVE-2018-15329: High severity riverbed steelapp traffic manager vulnerability
On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.7, or Enterprise Manager 3.1.1, when authenticated administrative users run commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-15329?
CVE-2018-15329 refers to a vulnerability on BIG-IP and Enterprise Manager where authenticated administrative users may be able to run unauthorized commands.
Which software versions are affected by CVE-2018-15329?
BIG-IP versions between 14.0.0 and 14.0.0.2, 13.0.0 and 13.1.1.1, and 12.1.0 and 12.1.3.7, as well as Enterprise Manager version 3.1.1 are affected by CVE-2018-15329.
What is the severity of CVE-2018-15329?
CVE-2018-15329 has a severity rating of 7.2, which is considered high.
How can I fix CVE-2018-15329?
To fix CVE-2018-15329, F5 recommends upgrading to a patched version of the affected software.
Where can I find more information about CVE-2018-15329?
You can find more information about CVE-2018-15329 at the following link: https://support.f5.com/csp/article/K61620494