CVE-2020-5880: Malicious File Upload
Om BIG-IP 15.0.0-15.0.1.3 and 14.1.0-14.1.2.3, the restjavad process may expose a way for attackers to upload arbitrary files on the BIG-IP system, bypassing the authorization system. Resulting error messages may also reveal internal paths of the server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5880?
CVE-2020-5880 has a high severity rating as it allows unauthorized file upload and may reveal sensitive server information.
How do I fix CVE-2020-5880?
To fix CVE-2020-5880, upgrade your F5 BIG-IP systems to versions 15.0.1.4 or later, or 14.1.2.4 or later.
What systems are affected by CVE-2020-5880?
CVE-2020-5880 affects F5 BIG-IP version 15.0.0 to 15.0.1.3 and version 14.1.0 to 14.1.2.3 across various modules.
What risks are associated with CVE-2020-5880?
The risks associated with CVE-2020-5880 include unauthorized access for file uploads and the potential exposure of internal server paths.
Is there a workaround for CVE-2020-5880 while waiting for a patch?
Currently, no specific workaround is published for CVE-2020-5880; the best action is to apply the recommended update as soon as possible.