CVE-2019-6660: High severity f5 access policy manager vulnerability
On BIG-IP 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.1, undisclosed HTTP requests may consume excessive amounts of systems resources which may lead to a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-6660?
CVE-2019-6660 is a vulnerability on F5 BIG-IP products that allows undisclosed HTTP requests to consume excessive system resources, potentially leading to a denial of service.
Which F5 BIG-IP products are affected by CVE-2019-6660?
F5 BIG-IP Access Policy Manager, F5 BIG-IP Advanced Firewall Manager, F5 BIG-IP Analytics, F5 BIG-IP Application Acceleration Manager, F5 BIG-IP Application Security Manager, F5 BIG-IP Domain Name System, F5 BIG-IP Edge Gateway, F5 BIG-IP Fraud Protection Service, F5 BIG-IP Global Traffic Manager, F5 BIG-IP Link Controller, F5 BIG-IP Local Traffic Manager, F5 BIG-IP Policy Enforcement Manager, F5 BIG-IP Webaccelerator are affected.
What is the severity of CVE-2019-6660?
CVE-2019-6660 has a severity of 7.5 (High).
How can I fix CVE-2019-6660?
Apply the appropriate patches provided by F5 Networks to mitigate the vulnerability.
Where can I find more information about CVE-2019-6660?
You can find more information about CVE-2019-6660 on the F5 Networks support website.