First published: Tue May 12 2020(Updated: )
In versions 7.1.5-7.1.9, there is use-after-free memory vulnerability in the BIG-IP Edge Client Windows ActiveX component.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Big-ip Access Policy Manager | >=11.6.1<=11.6.5.1 | |
F5 Big-ip Access Policy Manager | >=12.1.0<=12.1.5.1 | |
F5 Big-ip Access Policy Manager | >=13.1.0<=13.1.3.3 | |
F5 Big-ip Access Policy Manager | >=14.1.0<=14.1.2.5 | |
F5 Big-ip Access Policy Manager | >=15.0.0<=15.1.0.3 | |
F5 Big-ip Access Policy Manager Client | >=7.1.5<=7.1.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-5897.
The title of this vulnerability is 'In versions 7.1.5-7.1.9 there is use-after-free memory vulnerability in the BIG-IP Edge Client Windows ActiveX component.'
The severity of CVE-2020-5897 is high with a severity value of 8.8.
CVE-2020-5897 affects F5 Big-ip Access Policy Manager versions 11.6.1-11.6.5.1, 12.1.0-12.1.5.1, 13.1.0-13.1.3.3, 14.1.0-14.1.2.5, and 15.0.0-15.1.0.3, as well as F5 Big-ip Access Policy Manager Client versions 7.1.5-7.1.9.
To fix CVE-2020-5897, you should update the affected software to a version that is not vulnerable.