First published: Thu Sep 13 2018(Updated: )
On F5 WebSafe Alert Server 1.0.0-4.2.6, a malicious, authenticated user can execute code on the alert server by using a maliciously crafted payload.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 WebSafe | >=1.0.0<=4.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5545 has a high severity level due to the potential for unauthorized code execution by an authenticated user.
To fix CVE-2018-5545, update the F5 WebSafe Alert Server to a version above 4.2.6.
CVE-2018-5545 affects users of F5 WebSafe Alert Server versions 1.0.0 to 4.2.6.
No, only an authenticated user can exploit CVE-2018-5545.
An attacker can execute arbitrary code on the F5 WebSafe Alert Server by using a crafted payload.