CVE-2019-6641: Medium severity f5 access policy manager vulnerability
On BIG-IP 12.1.0-12.1.4.1, undisclosed requests can cause iControl REST processes to crash. The attack can only come from an authenticated user; all roles are capable of performing the attack. Unauthenticated users cannot perform this attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6641?
CVE-2019-6641 is a high severity vulnerability that can crash iControl REST processes on affected F5 BIG-IP versions when exploited by authenticated users.
How do I fix CVE-2019-6641?
To address CVE-2019-6641, you should upgrade your F5 BIG-IP software to version 12.1.5 or later.
Who can exploit CVE-2019-6641?
CVE-2019-6641 can be exploited by any authenticated user, regardless of their role on the affected F5 BIG-IP systems.
What are the affected versions for CVE-2019-6641?
The affected versions for CVE-2019-6641 are F5 BIG-IP versions 12.1.0 through 12.1.4.
What components are impacted by CVE-2019-6641?
CVE-2019-6641 impacts various F5 BIG-IP components, including Access Policy Manager, Advanced Firewall Manager, and Application Security Manager.