First published: Thu Mar 22 2018(Updated: )
On F5 BIG-IP versions 13.0.0 - 13.1.0.3 or 12.0.0 - 12.1.3.1, TMM may restart when processing a specifically crafted page through a virtual server with an associated PEM policy that has content insertion as an action.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP Policy Enforcement Manager | >=12.0.0<12.1.3.2 | |
F5 BIG-IP Policy Enforcement Manager | >=13.0.0<13.1.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5503 has been classified as a moderate severity vulnerability.
To remediate CVE-2018-5503, you should upgrade to F5 BIG-IP versions 12.1.3.2 or 13.1.0.4 and later.
CVE-2018-5503 affects F5 BIG-IP versions 13.0.0 to 13.1.0.3 and 12.0.0 to 12.1.3.1.
The impact of CVE-2018-5503 involves a potential restart of the TMM when processing specific crafted pages.
Exploitation of CVE-2018-5503 can be conducted remotely via a specially crafted page.