CVE-2018-15334: CSRF
A cross-site request forgery (CSRF) vulnerability in the APM webtop 11.2.1 or greater may allow attacker to force an APM webtop session to log out and require re-authentication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-15334?
CVE-2018-15334 is classified as a moderate severity vulnerability due to its ability to trigger session logouts through cross-site request forgery.
How do I fix CVE-2018-15334?
To mitigate CVE-2018-15334, ensure that you have upgraded your F5 Big-IP Access Policy Manager to the latest version beyond the affected versions outlined in the vulnerability report.
What versions are affected by CVE-2018-15334?
CVE-2018-15334 affects F5 Big-IP Access Policy Manager versions from 11.5.1 up to 14.1.0, including all versions in between.
What type of attack does CVE-2018-15334 involve?
CVE-2018-15334 involves a cross-site request forgery (CSRF) attack that can force an authenticated user to be logged out.
Can CVE-2018-15334 affect session management?
Yes, CVE-2018-15334 can disrupt session management by logging out users, requiring them to re-authenticate.