First published: Thu May 05 2022(Updated: )
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when an Internet Content Adaptation Protocol (ICAP) profile is configured on a virtual server, undisclosed traffic can cause an increase in Traffic Management Microkernel (TMM) memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Access Policy Manager | =11.6.1 | |
F5 Access Policy Manager | =11.6.2 | |
F5 Access Policy Manager | =11.6.3 | |
F5 Access Policy Manager | =11.6.4 | |
F5 Access Policy Manager | =11.6.5 | |
F5 Access Policy Manager | =12.1.0 | |
F5 Access Policy Manager | =12.1.1 | |
F5 Access Policy Manager | =12.1.2 | |
F5 Access Policy Manager | =12.1.3 | |
F5 Access Policy Manager | =12.1.4 | |
F5 Access Policy Manager | =12.1.5 | |
F5 Access Policy Manager | =12.1.6 | |
F5 Access Policy Manager | =13.1.0 | |
F5 Access Policy Manager | =13.1.1 | |
F5 Access Policy Manager | =13.1.3 | |
F5 Access Policy Manager | =13.1.4 | |
F5 Access Policy Manager | =13.1.5 | |
F5 Access Policy Manager | =14.1.0 | |
F5 Access Policy Manager | =14.1.2 | |
F5 Access Policy Manager | =14.1.3 | |
F5 Access Policy Manager | =14.1.4 | |
F5 Access Policy Manager | =15.1.0 | |
F5 Access Policy Manager | =15.1.1 | |
F5 Access Policy Manager | =15.1.2 | |
F5 Access Policy Manager | =15.1.3 | |
F5 Access Policy Manager | =15.1.4 | |
F5 Access Policy Manager | =15.1.5 | |
F5 Access Policy Manager | =16.1.0 | |
F5 Access Policy Manager | =16.1.1 | |
F5 Access Policy Manager | =16.1.2 | |
F5 Access Policy Manager | =17.0.0 | |
F5 BIG-IP Advanced Firewall Manager | =11.6.1 | |
F5 BIG-IP Advanced Firewall Manager | =11.6.2 | |
F5 BIG-IP Advanced Firewall Manager | =11.6.3 | |
F5 BIG-IP Advanced Firewall Manager | =11.6.4 | |
F5 BIG-IP Advanced Firewall Manager | =11.6.5 | |
F5 BIG-IP Advanced Firewall Manager | =12.1.0 | |
F5 BIG-IP Advanced Firewall Manager | =12.1.1 | |
F5 BIG-IP Advanced Firewall Manager | =12.1.2 | |
F5 BIG-IP Advanced Firewall Manager | =12.1.3 | |
F5 BIG-IP Advanced Firewall Manager | =12.1.4 | |
F5 BIG-IP Advanced Firewall Manager | =12.1.5 | |
F5 BIG-IP Advanced Firewall Manager | =12.1.6 | |
F5 BIG-IP Advanced Firewall Manager | =13.1.0 | |
F5 BIG-IP Advanced Firewall Manager | =13.1.1 | |
F5 BIG-IP Advanced Firewall Manager | =13.1.3 | |
F5 BIG-IP Advanced Firewall Manager | =13.1.4 | |
F5 BIG-IP Advanced Firewall Manager | =13.1.5 | |
F5 BIG-IP Advanced Firewall Manager | =14.1.0 | |
F5 BIG-IP Advanced Firewall Manager | =14.1.2 | |
F5 BIG-IP Advanced Firewall Manager | =14.1.3 | |
F5 BIG-IP Advanced Firewall Manager | =14.1.4 | |
F5 BIG-IP Advanced Firewall Manager | =15.1.0 | |
F5 BIG-IP Advanced Firewall Manager | =15.1.1 | |
F5 BIG-IP Advanced Firewall Manager | =15.1.2 | |
F5 BIG-IP Advanced Firewall Manager | =15.1.3 | |
F5 BIG-IP Advanced Firewall Manager | =15.1.4 | |
F5 BIG-IP Advanced Firewall Manager | =15.1.5 | |
F5 BIG-IP Advanced Firewall Manager | =16.1.0 | |
F5 BIG-IP Advanced Firewall Manager | =16.1.1 | |
F5 BIG-IP Advanced Firewall Manager | =16.1.2 | |
F5 BIG-IP Advanced Firewall Manager | =17.0.0 | |
F5 BIG-IP Analytics | =11.6.1 | |
F5 BIG-IP Analytics | =11.6.2 | |
F5 BIG-IP Analytics | =11.6.3 | |
F5 BIG-IP Analytics | =11.6.4 | |
F5 BIG-IP Analytics | =11.6.5 | |
F5 BIG-IP Analytics | =12.1.0 | |
F5 BIG-IP Analytics | =12.1.1 | |
F5 BIG-IP Analytics | =12.1.2 | |
F5 BIG-IP Analytics | =12.1.3 | |
F5 BIG-IP Analytics | =12.1.4 | |
F5 BIG-IP Analytics | =12.1.5 | |
F5 BIG-IP Analytics | =12.1.6 | |
F5 BIG-IP Analytics | =13.1.0 | |
F5 BIG-IP Analytics | =13.1.1 | |
F5 BIG-IP Analytics | =13.1.3 | |
F5 BIG-IP Analytics | =13.1.4 | |
F5 BIG-IP Analytics | =13.1.5 | |
F5 BIG-IP Analytics | =14.1.0 | |
F5 BIG-IP Analytics | =14.1.2 | |
F5 BIG-IP Analytics | =14.1.3 | |
F5 BIG-IP Analytics | =14.1.4 | |
F5 BIG-IP Analytics | =15.1.0 | |
F5 BIG-IP Analytics | =15.1.1 | |
F5 BIG-IP Analytics | =15.1.2 | |
F5 BIG-IP Analytics | =15.1.3 | |
F5 BIG-IP Analytics | =15.1.4 | |
F5 BIG-IP Analytics | =15.1.5 | |
F5 BIG-IP Analytics | =16.1.0 | |
F5 BIG-IP Analytics | =16.1.1 | |
F5 BIG-IP Analytics | =16.1.2 | |
F5 BIG-IP Analytics | =17.0.0 | |
F5 BIG-IP Application Acceleration Manager | =11.6.1 | |
F5 BIG-IP Application Acceleration Manager | =11.6.2 | |
F5 BIG-IP Application Acceleration Manager | =11.6.3 | |
F5 BIG-IP Application Acceleration Manager | =11.6.4 | |
F5 BIG-IP Application Acceleration Manager | =11.6.5 | |
F5 BIG-IP Application Acceleration Manager | =12.1.0 | |
F5 BIG-IP Application Acceleration Manager | =12.1.1 | |
F5 BIG-IP Application Acceleration Manager | =12.1.2 | |
F5 BIG-IP Application Acceleration Manager | =12.1.3 | |
F5 BIG-IP Application Acceleration Manager | =12.1.4 | |
F5 BIG-IP Application Acceleration Manager | =12.1.5 | |
F5 BIG-IP Application Acceleration Manager | =12.1.6 | |
F5 BIG-IP Application Acceleration Manager | =13.1.0 | |
F5 BIG-IP Application Acceleration Manager | =13.1.1 | |
F5 BIG-IP Application Acceleration Manager | =13.1.3 | |
F5 BIG-IP Application Acceleration Manager | =13.1.4 | |
F5 BIG-IP Application Acceleration Manager | =13.1.5 | |
F5 BIG-IP Application Acceleration Manager | =14.1.0 | |
F5 BIG-IP Application Acceleration Manager | =14.1.2 | |
F5 BIG-IP Application Acceleration Manager | =14.1.3 | |
F5 BIG-IP Application Acceleration Manager | =14.1.4 | |
F5 BIG-IP Application Acceleration Manager | =15.1.0 | |
F5 BIG-IP Application Acceleration Manager | =15.1.1 | |
F5 BIG-IP Application Acceleration Manager | =15.1.2 | |
F5 BIG-IP Application Acceleration Manager | =15.1.3 | |
F5 BIG-IP Application Acceleration Manager | =15.1.4 | |
F5 BIG-IP Application Acceleration Manager | =15.1.5 | |
F5 BIG-IP Application Acceleration Manager | =16.1.0 | |
F5 BIG-IP Application Acceleration Manager | =16.1.1 | |
F5 BIG-IP Application Acceleration Manager | =16.1.2 | |
F5 BIG-IP Application Acceleration Manager | =17.0.0 | |
F5 Application Security Manager | =11.6.1 | |
F5 Application Security Manager | =11.6.2 | |
F5 Application Security Manager | =11.6.3 | |
F5 Application Security Manager | =11.6.4 | |
F5 Application Security Manager | =11.6.5 | |
F5 Application Security Manager | =12.1.0 | |
F5 Application Security Manager | =12.1.1 | |
F5 Application Security Manager | =12.1.2 | |
F5 Application Security Manager | =12.1.3 | |
F5 Application Security Manager | =12.1.4 | |
F5 Application Security Manager | =12.1.5 | |
F5 Application Security Manager | =12.1.6 | |
F5 Application Security Manager | =13.1.0 | |
F5 Application Security Manager | =13.1.1 | |
F5 Application Security Manager | =13.1.3 | |
F5 Application Security Manager | =13.1.4 | |
F5 Application Security Manager | =13.1.5 | |
F5 Application Security Manager | =14.1.0 | |
F5 Application Security Manager | =14.1.2 | |
F5 Application Security Manager | =14.1.3 | |
F5 Application Security Manager | =14.1.4 | |
F5 Application Security Manager | =15.1.0 | |
F5 Application Security Manager | =15.1.1 | |
F5 Application Security Manager | =15.1.2 | |
F5 Application Security Manager | =15.1.3 | |
F5 Application Security Manager | =15.1.4 | |
F5 Application Security Manager | =15.1.5 | |
F5 Application Security Manager | =16.1.0 | |
F5 Application Security Manager | =16.1.1 | |
F5 Application Security Manager | =16.1.2 | |
F5 Application Security Manager | =17.0.0 | |
F5 BIG-IP | =11.6.1 | |
F5 BIG-IP | =11.6.2 | |
F5 BIG-IP | =11.6.3 | |
F5 BIG-IP | =11.6.4 | |
F5 BIG-IP | =11.6.5 | |
F5 BIG-IP | =12.1.0 | |
F5 BIG-IP | =12.1.1 | |
F5 BIG-IP | =12.1.2 | |
F5 BIG-IP | =12.1.3 | |
F5 BIG-IP | =12.1.4 | |
F5 BIG-IP | =12.1.5 | |
F5 BIG-IP | =12.1.6 | |
F5 BIG-IP | =13.1.0 | |
F5 BIG-IP | =13.1.1 | |
F5 BIG-IP | =13.1.3 | |
F5 BIG-IP | =13.1.4 | |
F5 BIG-IP | =13.1.5 | |
F5 BIG-IP | =14.1.0 | |
F5 BIG-IP | =14.1.2 | |
F5 BIG-IP | =14.1.3 | |
F5 BIG-IP | =14.1.4 | |
F5 BIG-IP | =15.1.0 | |
F5 BIG-IP | =15.1.1 | |
F5 BIG-IP | =15.1.2 | |
F5 BIG-IP | =15.1.3 | |
F5 BIG-IP | =15.1.4 | |
F5 BIG-IP | =15.1.5 | |
F5 BIG-IP | =16.1.0 | |
F5 BIG-IP | =16.1.1 | |
F5 BIG-IP | =16.1.2 | |
F5 BIG-IP | =17.0.0 | |
F5 BIG-IP Fraud Protection Service | =11.6.1 | |
F5 BIG-IP Fraud Protection Service | =11.6.2 | |
F5 BIG-IP Fraud Protection Service | =11.6.3 | |
F5 BIG-IP Fraud Protection Service | =11.6.4 | |
F5 BIG-IP Fraud Protection Service | =11.6.5 | |
F5 BIG-IP Fraud Protection Service | =12.1.0 | |
F5 BIG-IP Fraud Protection Service | =12.1.1 | |
F5 BIG-IP Fraud Protection Service | =12.1.2 | |
F5 BIG-IP Fraud Protection Service | =12.1.3 | |
F5 BIG-IP Fraud Protection Service | =12.1.4 | |
F5 BIG-IP Fraud Protection Service | =12.1.5 | |
F5 BIG-IP Fraud Protection Service | =12.1.6 | |
F5 BIG-IP Fraud Protection Service | =13.1.0 | |
F5 BIG-IP Fraud Protection Service | =13.1.1 | |
F5 BIG-IP Fraud Protection Service | =13.1.3 | |
F5 BIG-IP Fraud Protection Service | =13.1.4 | |
F5 BIG-IP Fraud Protection Service | =13.1.5 | |
F5 BIG-IP Fraud Protection Service | =14.1.0 | |
F5 BIG-IP Fraud Protection Service | =14.1.2 | |
F5 BIG-IP Fraud Protection Service | =14.1.3 | |
F5 BIG-IP Fraud Protection Service | =14.1.4 | |
F5 BIG-IP Fraud Protection Service | =15.1.0 | |
F5 BIG-IP Fraud Protection Service | =15.1.1 | |
F5 BIG-IP Fraud Protection Service | =15.1.2 | |
F5 BIG-IP Fraud Protection Service | =15.1.3 | |
F5 BIG-IP Fraud Protection Service | =15.1.4 | |
F5 BIG-IP Fraud Protection Service | =15.1.5 | |
F5 BIG-IP Fraud Protection Service | =16.1.0 | |
F5 BIG-IP Fraud Protection Service | =16.1.1 | |
F5 BIG-IP Fraud Protection Service | =16.1.2 | |
F5 BIG-IP Fraud Protection Service | =17.0.0 | |
Riverbed SteelApp Traffic Manager | =11.6.1 | |
Riverbed SteelApp Traffic Manager | =11.6.2 | |
Riverbed SteelApp Traffic Manager | =11.6.3 | |
Riverbed SteelApp Traffic Manager | =11.6.4 | |
Riverbed SteelApp Traffic Manager | =11.6.5 | |
Riverbed SteelApp Traffic Manager | =12.1.0 | |
Riverbed SteelApp Traffic Manager | =12.1.1 | |
Riverbed SteelApp Traffic Manager | =12.1.2 | |
Riverbed SteelApp Traffic Manager | =12.1.3 | |
Riverbed SteelApp Traffic Manager | =12.1.4 | |
Riverbed SteelApp Traffic Manager | =12.1.5 | |
Riverbed SteelApp Traffic Manager | =12.1.6 | |
Riverbed SteelApp Traffic Manager | =13.1.0 | |
Riverbed SteelApp Traffic Manager | =13.1.1 | |
Riverbed SteelApp Traffic Manager | =13.1.3 | |
Riverbed SteelApp Traffic Manager | =13.1.4 | |
Riverbed SteelApp Traffic Manager | =13.1.5 | |
Riverbed SteelApp Traffic Manager | =14.1.0 | |
Riverbed SteelApp Traffic Manager | =14.1.2 | |
Riverbed SteelApp Traffic Manager | =14.1.3 | |
Riverbed SteelApp Traffic Manager | =14.1.4 | |
Riverbed SteelApp Traffic Manager | =15.1.0 | |
Riverbed SteelApp Traffic Manager | =15.1.1 | |
Riverbed SteelApp Traffic Manager | =15.1.2 | |
Riverbed SteelApp Traffic Manager | =15.1.3 | |
Riverbed SteelApp Traffic Manager | =15.1.4 | |
Riverbed SteelApp Traffic Manager | =15.1.5 | |
Riverbed SteelApp Traffic Manager | =16.1.0 | |
Riverbed SteelApp Traffic Manager | =16.1.1 | |
Riverbed SteelApp Traffic Manager | =16.1.2 | |
Riverbed SteelApp Traffic Manager | =17.0.0 | |
F5 BIG-IP Link Controller | =11.6.1 | |
F5 BIG-IP Link Controller | =11.6.2 | |
F5 BIG-IP Link Controller | =11.6.3 | |
F5 BIG-IP Link Controller | =11.6.4 | |
F5 BIG-IP Link Controller | =11.6.5 | |
F5 BIG-IP Link Controller | =12.1.0 | |
F5 BIG-IP Link Controller | =12.1.1 | |
F5 BIG-IP Link Controller | =12.1.2 | |
F5 BIG-IP Link Controller | =12.1.3 | |
F5 BIG-IP Link Controller | =12.1.4 | |
F5 BIG-IP Link Controller | =12.1.5 | |
F5 BIG-IP Link Controller | =12.1.6 | |
F5 BIG-IP Link Controller | =13.1.0 | |
F5 BIG-IP Link Controller | =13.1.1 | |
F5 BIG-IP Link Controller | =13.1.3 | |
F5 BIG-IP Link Controller | =13.1.4 | |
F5 BIG-IP Link Controller | =13.1.5 | |
F5 BIG-IP Link Controller | =14.1.0 | |
F5 BIG-IP Link Controller | =14.1.2 | |
F5 BIG-IP Link Controller | =14.1.3 | |
F5 BIG-IP Link Controller | =14.1.4 | |
F5 BIG-IP Link Controller | =15.1.0 | |
F5 BIG-IP Link Controller | =15.1.1 | |
F5 BIG-IP Link Controller | =15.1.2 | |
F5 BIG-IP Link Controller | =15.1.3 | |
F5 BIG-IP Link Controller | =15.1.4 | |
F5 BIG-IP Link Controller | =15.1.5 | |
F5 BIG-IP Link Controller | =16.1.0 | |
F5 BIG-IP Link Controller | =16.1.1 | |
F5 BIG-IP Link Controller | =16.1.2 | |
F5 BIG-IP Link Controller | =17.0.0 | |
Riverbed SteelApp Traffic Manager | =11.6.1 | |
Riverbed SteelApp Traffic Manager | =11.6.2 | |
Riverbed SteelApp Traffic Manager | =11.6.3 | |
Riverbed SteelApp Traffic Manager | =11.6.4 | |
Riverbed SteelApp Traffic Manager | =11.6.5 | |
Riverbed SteelApp Traffic Manager | =12.1.0 | |
Riverbed SteelApp Traffic Manager | =12.1.1 | |
Riverbed SteelApp Traffic Manager | =12.1.2 | |
Riverbed SteelApp Traffic Manager | =12.1.3 | |
Riverbed SteelApp Traffic Manager | =12.1.4 | |
Riverbed SteelApp Traffic Manager | =12.1.5 | |
Riverbed SteelApp Traffic Manager | =12.1.6 | |
Riverbed SteelApp Traffic Manager | =13.1.0 | |
Riverbed SteelApp Traffic Manager | =13.1.1 | |
Riverbed SteelApp Traffic Manager | =13.1.3 | |
Riverbed SteelApp Traffic Manager | =13.1.4 | |
Riverbed SteelApp Traffic Manager | =13.1.5 | |
Riverbed SteelApp Traffic Manager | =14.1.0 | |
Riverbed SteelApp Traffic Manager | =14.1.2 | |
Riverbed SteelApp Traffic Manager | =14.1.3 | |
Riverbed SteelApp Traffic Manager | =14.1.4 | |
Riverbed SteelApp Traffic Manager | =15.1.0 | |
Riverbed SteelApp Traffic Manager | =15.1.1 | |
Riverbed SteelApp Traffic Manager | =15.1.2 | |
Riverbed SteelApp Traffic Manager | =15.1.3 | |
Riverbed SteelApp Traffic Manager | =15.1.4 | |
Riverbed SteelApp Traffic Manager | =15.1.5 | |
Riverbed SteelApp Traffic Manager | =16.1.0 | |
Riverbed SteelApp Traffic Manager | =16.1.1 | |
Riverbed SteelApp Traffic Manager | =16.1.2 | |
Riverbed SteelApp Traffic Manager | =17.0.0 | |
F5 BIG-IP Policy Enforcement Manager | =11.6.1 | |
F5 BIG-IP Policy Enforcement Manager | =11.6.2 | |
F5 BIG-IP Policy Enforcement Manager | =11.6.3 | |
F5 BIG-IP Policy Enforcement Manager | =11.6.4 | |
F5 BIG-IP Policy Enforcement Manager | =11.6.5 | |
F5 BIG-IP Policy Enforcement Manager | =12.1.0 | |
F5 BIG-IP Policy Enforcement Manager | =12.1.1 | |
F5 BIG-IP Policy Enforcement Manager | =12.1.2 | |
F5 BIG-IP Policy Enforcement Manager | =12.1.3 | |
F5 BIG-IP Policy Enforcement Manager | =12.1.4 | |
F5 BIG-IP Policy Enforcement Manager | =12.1.5 | |
F5 BIG-IP Policy Enforcement Manager | =12.1.6 | |
F5 BIG-IP Policy Enforcement Manager | =13.1.0 | |
F5 BIG-IP Policy Enforcement Manager | =13.1.1 | |
F5 BIG-IP Policy Enforcement Manager | =13.1.3 | |
F5 BIG-IP Policy Enforcement Manager | =13.1.4 | |
F5 BIG-IP Policy Enforcement Manager | =13.1.5 | |
F5 BIG-IP Policy Enforcement Manager | =14.1.0 | |
F5 BIG-IP Policy Enforcement Manager | =14.1.2 | |
F5 BIG-IP Policy Enforcement Manager | =14.1.3 | |
F5 BIG-IP Policy Enforcement Manager | =14.1.4 | |
F5 BIG-IP Policy Enforcement Manager | =15.1.0 | |
F5 BIG-IP Policy Enforcement Manager | =15.1.1 | |
F5 BIG-IP Policy Enforcement Manager | =15.1.2 | |
F5 BIG-IP Policy Enforcement Manager | =15.1.3 | |
F5 BIG-IP Policy Enforcement Manager | =15.1.4 | |
F5 BIG-IP Policy Enforcement Manager | =15.1.5 | |
F5 BIG-IP Policy Enforcement Manager | =16.1.0 | |
F5 BIG-IP Policy Enforcement Manager | =16.1.1 | |
F5 BIG-IP Policy Enforcement Manager | =16.1.2 | |
F5 BIG-IP Policy Enforcement Manager | =17.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27189 is rated as high severity due to the potential for unauthorized access and manipulation of data.
To mitigate CVE-2022-27189, upgrade to F5 BIG-IP version 16.1.2.2 or later, 15.1.5.1 or later, or 14.1.4.6 or later.
CVE-2022-27189 affects F5 BIG-IP versions 16.1.x prior to 16.1.2.2, 15.1.x prior to 15.1.5.1, 14.1.x prior to 14.1.4.6, 13.1.x prior to 13.1.5, and all versions of 12.1.x and 11.6.x.
CVE-2022-27189 is a vulnerability associated with the Internet Content Adaptation Protocol (ICAP) profile configuration on virtual servers.
Yes, F5 has released patches for CVE-2022-27189 in the latest versions of affected software.