CVE-2022-23021: Null Pointer Dereference
On BIG-IP version 16.1.x before 16.1.2, when any of the following configurations are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate: HTTP redirect rule in an LTM policy, BIG-IP APM Access Profile, and Explicit HTTP Proxy in HTTP Profile. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23021?
The severity of CVE-2022-23021 is high with a severity value of 7.5.
Which software versions are affected by CVE-2022-23021?
CVE-2022-23021 affects BIG-IP versions 16.1.x before 16.1.2.
How can CVE-2022-23021 be exploited?
CVE-2022-23021 can be exploited by sending undisclosed requests to a virtual server with specific configurations.
What can cause the Traffic Management Microkernel (TMM) to terminate in CVE-2022-23021?
The Traffic Management Microkernel (TMM) can terminate in CVE-2022-23021 if any of the following configurations are configured on a virtual server: HTTP redirect rule in an LTM policy, BIG-IP APM Access Profile, and Explicit HTTP Proxy in HTTP P.
Is there a fix available for CVE-2022-23021?
Yes, a fix for CVE-2022-23021 is available in BIG-IP version 16.1.2.