CVE-2018-15335: Medium severity f5 access policy manager vulnerability
When APM 13.0.0-13.1.x is deployed as an OAuth Resource Server, APM becomes a client application to an external OAuth authorization server. In certain cases when communication between the BIG-IP APM and the OAuth authorization server is lost, APM may not display the intended message in the failure response
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-15335?
CVE-2018-15335 is considered a moderate severity vulnerability due to its potential impact on communication failure with OAuth authorization servers.
How do I fix CVE-2018-15335?
To fix CVE-2018-15335, upgrade the F5 BIG-IP Access Policy Manager to version 13.1.1 or later.
What versions of F5 BIG-IP Access Policy Manager are affected by CVE-2018-15335?
F5 BIG-IP Access Policy Manager versions 13.0.0 to 13.1.0 are affected by CVE-2018-15335.
What is the impact of CVE-2018-15335?
The impact of CVE-2018-15335 includes potential improper error messaging during OAuth authorization failures.
Is there a workaround for CVE-2018-15335?
There are no official workarounds for CVE-2018-15335; upgrading to the latest version is recommended.