CVE-2022-33203: BIG-IP APM and F5 SSL Orchestrator vulnerability CVE-2022-33203
In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when a BIG-IP APM access policy with Service Connect agent is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-33203?
CVE-2022-33203 is a vulnerability in BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5 that can cause an increase in memory resource utilization when a BIG-IP APM access policy with Service Connect agent is configured on a virtual server.
How severe is CVE-2022-33203?
CVE-2022-33203 has a high severity rating with a CVSS score of 7.5.
Which software versions are affected by CVE-2022-33203?
CVE-2022-33203 affects BIG-IP Access Policy Manager versions 14.1.x, 15.1.x, and 16.1.x, as well as BIG-IP SSL Orchestrator versions 14.1.x, 15.1.x, and 16.1.x.
What is the fix for CVE-2022-33203?
To fix CVE-2022-33203, update BIG-IP software to version 14.1.5, 15.1.6.1, or 16.1.3.
Where can I find more information about CVE-2022-33203?
More information about CVE-2022-33203 can be found at the following link: [https://support.f5.com/csp/article/K52534925]