CVE-2021-23036: Input Validation
On version 16.0.x before 16.0.1.2, when a BIG-IP ASM and DataSafe profile are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-23036?
CVE-2021-23036 is a vulnerability that affects F5 BIG-IP Advanced Web Application Firewall, F5 BIG-IP Application Security Manager, and F5 Big-IP Datasafe versions 16.0.x before 16.0.1.2.
What is the severity of CVE-2021-23036?
CVE-2021-23036 has a severity rating of 7.5 (high).
How does CVE-2021-23036 affect F5 BIG-IP?
CVE-2021-23036 can cause the Traffic Management Microkernel (TMM) to terminate when a BIG-IP ASM and DataSafe profile are configured on a virtual server.
Which versions of F5 BIG-IP are affected by CVE-2021-23036?
Versions 16.0.x before 16.0.1.2 of F5 BIG-IP Advanced Web Application Firewall, F5 BIG-IP Application Security Manager, and F5 Big-IP Datasafe are affected by CVE-2021-23036.
How can I fix CVE-2021-23036?
To fix CVE-2021-23036, you need to update your F5 BIG-IP software to version 16.0.1.2 or later.