CVE-2021-22985: High severity F5 BIG-IP Application Security Manager vulnerability
On BIG-IP APM version 16.0.x before 16.0.1.1, under certain conditions, when processing VPN traffic with APM, TMM consumes excessive memory. A malicious, authenticated VPN user may abuse this to perform a DoS attack against the APM. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-22985?
CVE-2021-22985 is rated as a medium severity vulnerability due to its potential for causing DoS attacks.
How do I fix CVE-2021-22985?
To fix CVE-2021-22985, upgrade to BIG-IP APM version 16.0.1.1 or later.
Who is affected by CVE-2021-22985?
CVE-2021-22985 affects users on BIG-IP APM versions prior to 16.0.1.1 within specific version ranges.
What is the impact of CVE-2021-22985?
The impact of CVE-2021-22985 includes excessive memory consumption by TMM, potentially allowing a DoS attack.
Is there a workaround for CVE-2021-22985?
There is no official workaround for CVE-2021-22985; an upgrade to the patched version is required.