CVE-2020-5883: High severity f5 access policy manager vulnerability
On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, when a virtual server is configured with HTTP explicit proxy and has an attached HTTPPROXYREQUEST iRule, POST requests sent to the virtual server cause an xdata memory leak.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-5883.
What is the severity of CVE-2020-5883?
The severity of CVE-2020-5883 is high.
Which software versions are affected by CVE-2020-5883?
CVE-2020-5883 affects the following software versions: F5 BIG-IP Access Policy Manager, F5 BIG-IP Advanced Firewall Manager, F5 Big-ip Webaccelerator, F5 Big-ip Application Acceleration Manager, F5 BIG-IP Application Security Manager, F5 Big-ip Fraud Protection Service, F5 Big-ip Edge Gateway, F5 Big-ip Link Controller, F5 Big-ip Local Traffic Manager, F5 Big-ip Policy Enforcement Manager.
How can I fix CVE-2020-5883?
To fix CVE-2020-5883, you should upgrade to the patched versions of the affected software.
Where can I find more information about CVE-2020-5883?
More information about CVE-2020-5883 can be found at the following link: https://support.f5.com/csp/article/K12234501