First published: Thu Dec 20 2018(Updated: )
On BIG-IP AAM 13.0.0 or 12.1.0-12.1.3.7, the dcdb_convert utility used by BIG-IP AAM fails to drop group permissions when executing helper scripts, which could be used to leverage attacks against the BIG-IP system.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP Application Acceleration Manager | >=12.1.0<=12.1.3 | |
F5 BIG-IP Application Acceleration Manager | =13.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15331 has a high severity rating due to its potential to allow attackers to exploit system vulnerabilities.
To fix CVE-2018-15331, update your F5 BIG-IP AAM to the latest version that addresses this vulnerability.
CVE-2018-15331 affects F5 BIG-IP Application Acceleration Manager versions 12.1.0 to 12.1.3.7 and version 13.0.0.
CVE-2018-15331 is a privilege escalation vulnerability related to improper group permissions in the dcdb_convert utility.
F5 recommends applying patches and updates as the primary method to mitigate the risk associated with CVE-2018-15331.