CVE-2018-15331: High severity F5 Big-ip Application Acceleration Manager vulnerability
On BIG-IP AAM 13.0.0 or 12.1.0-12.1.3.7, the dcdbconvert utility used by BIG-IP AAM fails to drop group permissions when executing helper scripts, which could be used to leverage attacks against the BIG-IP system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-15331?
CVE-2018-15331 has a high severity rating due to its potential to allow attackers to exploit system vulnerabilities.
How do I fix CVE-2018-15331?
To fix CVE-2018-15331, update your F5 BIG-IP AAM to the latest version that addresses this vulnerability.
What products are affected by CVE-2018-15331?
CVE-2018-15331 affects F5 BIG-IP Application Acceleration Manager versions 12.1.0 to 12.1.3.7 and version 13.0.0.
What type of vulnerability is CVE-2018-15331?
CVE-2018-15331 is a privilege escalation vulnerability related to improper group permissions in the dcdb_convert utility.
Is there any workaround for CVE-2018-15331?
F5 recommends applying patches and updates as the primary method to mitigate the risk associated with CVE-2018-15331.