CVE-2020-5897: Use After Free
Published May 12, 2020
·Updated
In versions 7.1.5-7.1.9, there is use-after-free memory vulnerability in the BIG-IP Edge Client Windows ActiveX component.
Affected Software
6 affected components
F5 BIG-IP Access Policy Manager>=11.6.1<=11.6.5.1
F5 BIG-IP Access Policy Manager>=12.1.0<=12.1.5.1
F5 BIG-IP Access Policy Manager>=13.1.0<=13.1.3.3
F5 BIG-IP Access Policy Manager>=14.1.0<=14.1.2.5
F5 BIG-IP Access Policy Manager>=15.0.0<=15.1.0.3
F5 Big-ip Access Policy Manager Client>=7.1.5<=7.1.9
Event History
May 12, 2020
CVE Published
via MITRE·03:20 PM
Data Sourced
via MITRE·03:20 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-5897.
2
What is the title of this vulnerability?
The title of this vulnerability is 'In versions 7.1.5-7.1.9 there is use-after-free memory vulnerability in the BIG-IP Edge Client Windows ActiveX component.'
3
What is the severity of CVE-2020-5897?
The severity of CVE-2020-5897 is high with a severity value of 8.8.
4
What software is affected by CVE-2020-5897?
CVE-2020-5897 affects F5 Big-ip Access Policy Manager versions 11.6.1-11.6.5.1, 12.1.0-12.1.5.1, 13.1.0-13.1.3.3, 14.1.0-14.1.2.5, and 15.0.0-15.1.0.3, as well as F5 Big-ip Access Policy Manager Client versions 7.1.5-7.1.9.
5
How can I fix CVE-2020-5897?
To fix CVE-2020-5897, you should update the affected software to a version that is not vulnerable.