CVE-2019-6658: SQL Injection
Published Nov 1, 2019
·Updated
On BIG-IP AFM 15.0.0-15.0.1, 14.0.0-14.1.2, 13.1.0-13.1.3.1, and 12.1.0-12.1.5, a vulnerability in the AFM configuration utility may allow any authenticated BIG-IP user to run an SQL injection attack.
Affected Software
4 affected components
F5 BIG-IP Advanced Firewall Manager>=12.1.0<=12.1.5
F5 BIG-IP Advanced Firewall Manager>=13.1.0<=13.1.3
F5 BIG-IP Advanced Firewall Manager>=14.0.0<14.1.2.1
F5 BIG-IP Advanced Firewall Manager>=15.0.0<=15.0.1
Event History
Nov 1, 2019
CVE Published
via MITRE·02:59 PM
Data Sourced
via MITRE·02:59 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-6658?
CVE-2019-6658 is considered a high severity vulnerability due to its potential for SQL injection attacks.
2
How do I fix CVE-2019-6658?
To address CVE-2019-6658, upgrade to versions 12.1.6 or later, 13.1.4 or later, 14.1.3 or later, or 15.1.0 or later of F5 BIG-IP Advanced Firewall Manager.
3
Who is affected by CVE-2019-6658?
CVE-2019-6658 affects authenticated users of F5 BIG-IP Advanced Firewall Manager versions between 12.1.0 and 15.0.1.
4
What kind of attack can be executed due to CVE-2019-6658?
CVE-2019-6658 allows authenticated users to conduct SQL injection attacks via the AFM configuration utility.
5
When was CVE-2019-6658 disclosed?
CVE-2019-6658 was publicly disclosed in January 2019.