CVE-2020-27729: Medium severity f5 access policy manager vulnerability
In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, an undisclosed link on the BIG-IP APM virtual server allows a malicious user to build an open redirect URI.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-27729?
CVE-2020-27729 is rated as a high severity vulnerability due to the potential for open redirects.
How do I fix CVE-2020-27729?
To fix CVE-2020-27729, upgrade your F5 BIG-IP APM to a version that is not vulnerable, specifically above the affected versions listed.
What versions are affected by CVE-2020-27729?
CVE-2020-27729 affects F5 BIG-IP APM versions 11.6.1 through 11.6.5.2, 12.1.0 through 12.1.5.2, 13.1.0 through 13.1.3.4, 14.1.0 through 14.1.3.1, 15.0.0 through 15.1.0, and 16.0.0 through 16.0.0.1.
What impact does CVE-2020-27729 have?
CVE-2020-27729 allows malicious users to construct open redirect URIs, potentially redirecting users to malicious sites.
Is there a workaround for CVE-2020-27729?
While the best course of action is to upgrade, implementing strict input validation and disabling untrusted redirect functionality can help mitigate CVE-2020-27729.