CVE-2019-6614: Medium severity f5 access policy manager vulnerability
On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, internal methods used to prevent arbitrary file overwrites in Appliance Mode were not fully effective. An authenticated attacker with a high privilege level may be able to bypass protections implemented in appliance mode to overwrite arbitrary system files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6614?
CVE-2019-6614 has a severity rating of high due to the potential for an authenticated attacker to exploit it.
How do I fix CVE-2019-6614?
To remediate CVE-2019-6614, it is recommended to upgrade to the latest patched version of F5 BIG-IP products.
What systems are affected by CVE-2019-6614?
CVE-2019-6614 affects F5 BIG-IP versions ranging from 12.1.0 to 14.1.0 on various modules including Access Policy Manager and Application Security Manager.
Can an attacker exploit CVE-2019-6614 without authentication?
No, an attacker must have a high privilege account to exploit the vulnerability in CVE-2019-6614.
What type of vulnerability is CVE-2019-6614 classified as?
CVE-2019-6614 is classified as an arbitrary file overwrite vulnerability.