First published: Wed May 04 2022(Updated: )
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, when the stream profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP Access Policy Manager | =16.1.0 | |
F5 BIG-IP Access Policy Manager | =16.1.1 | |
F5 BIG-IP Access Policy Manager | =16.1.2 | |
F5 BIG-IP Advanced Firewall Manager | =16.1.0 | |
F5 BIG-IP Advanced Firewall Manager | =16.1.1 | |
F5 BIG-IP Advanced Firewall Manager | =16.1.2 | |
F5 BIG-IP Analytics | =16.1.0 | |
F5 BIG-IP Analytics | =16.1.1 | |
F5 BIG-IP Analytics | =16.1.2 | |
F5 Big-ip Application Acceleration Manager | =16.1.0 | |
F5 Big-ip Application Acceleration Manager | =16.1.1 | |
F5 Big-ip Application Acceleration Manager | =16.1.2 | |
F5 BIG-IP Application Security Manager | =16.1.0 | |
F5 BIG-IP Application Security Manager | =16.1.1 | |
F5 BIG-IP Application Security Manager | =16.1.2 | |
F5 Big-ip Domain Name System | =16.1.0 | |
F5 Big-ip Domain Name System | =16.1.1 | |
F5 Big-ip Domain Name System | =16.1.2 | |
F5 Big-ip Domain Name System | =17.0.0 | |
F5 Big-ip Fraud Protection Service | =16.1.0 | |
F5 Big-ip Fraud Protection Service | =16.1.1 | |
F5 Big-ip Fraud Protection Service | =16.1.2 | |
F5 Big-ip Global Traffic Manager | =16.1.0 | |
F5 Big-ip Global Traffic Manager | =16.1.1 | |
F5 Big-ip Global Traffic Manager | =16.1.2 | |
F5 Big-ip Link Controller | =16.1.0 | |
F5 Big-ip Link Controller | =16.1.1 | |
F5 Big-ip Link Controller | =16.1.2 | |
F5 Big-ip Local Traffic Manager | =16.1.0 | |
F5 Big-ip Local Traffic Manager | =16.1.1 | |
F5 Big-ip Local Traffic Manager | =16.1.2 | |
F5 Big-ip Policy Enforcement Manager | =16.1.0 | |
F5 Big-ip Policy Enforcement Manager | =16.1.1 | |
F5 Big-ip Policy Enforcement Manager | =16.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28701 is a vulnerability on F5 BIG-IP 16.1.x versions prior to 16.1.2.2 where undisclosed requests can cause an increase in memory resource utilization.
Vulnerability CVE-2022-28701 has a severity score of 7.5, which is considered high.
Software versions F5 BIG-IP Access Policy Manager 16.1.0, 16.1.1, 16.1.2, F5 BIG-IP Advanced Firewall Manager 16.1.0, 16.1.1, 16.1.2, F5 BIG-IP Analytics 16.1.0, 16.1.1, 16.1.2, F5 Big-ip Application Acceleration Manager 16.1.0, 16.1.1, 16.1.2, F5 BIG-IP Application Security Manager 16.1.0, 16.1.1, 16.1.2, F5 Big-ip Domain Name System 16.1.0, 16.1.1, 16.1.2, 17.0.0, F5 Big-ip Fraud Protection Service 16.1.0, 16.1.1, 16.1.2, F5 Big-ip Global Traffic Manager 16.1.0, 16.1.1, 16.1.2, F5 Big-ip Link Controller 16.1.0, 16.1.1, 16.1.2, F5 Big-ip Local Traffic Manager 16.1.0, 16.1.1, 16.1.2, F5 Big-ip Policy Enforcement Manager 16.1.0, 16.1.1, 16.1.2 are affected by vulnerability CVE-2022-28701.
To fix vulnerability CVE-2022-28701, update your F5 BIG-IP software to version 16.1.2.2 or a later version.
You can find more information about vulnerability CVE-2022-28701 on the F5 support website: [link](https://support.f5.com/csp/article/K99123750)