First published: Tue Sep 14 2021(Updated: )
On version 16.0.x before 16.0.1.2, when a BIG-IP ASM and DataSafe profile are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Big-ip Advanced Web Application Firewall | >=16.0.0<=16.0.1 | |
F5 BIG-IP Application Security Manager | >=16.0.0<=16.0.1 | |
F5 Big-ip Datasafe | >=16.0.0<=16.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23036 is a vulnerability that affects F5 BIG-IP Advanced Web Application Firewall, F5 BIG-IP Application Security Manager, and F5 Big-IP Datasafe versions 16.0.x before 16.0.1.2.
CVE-2021-23036 has a severity rating of 7.5 (high).
CVE-2021-23036 can cause the Traffic Management Microkernel (TMM) to terminate when a BIG-IP ASM and DataSafe profile are configured on a virtual server.
Versions 16.0.x before 16.0.1.2 of F5 BIG-IP Advanced Web Application Firewall, F5 BIG-IP Application Security Manager, and F5 Big-IP Datasafe are affected by CVE-2021-23036.
To fix CVE-2021-23036, you need to update your F5 BIG-IP software to version 16.0.1.2 or later.