CVE-2022-35236: HTTP2 profile vulnerability CVE-2022-35236
In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an HTTP2 profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-35236?
CVE-2022-35236 is a vulnerability in BIG-IP versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5 that allows undisclosed traffic to cause an increase in memory resource utilization.
How does CVE-2022-35236 affect F5 BIG-IP Access Policy Manager?
CVE-2022-35236 affects F5 BIG-IP Access Policy Manager versions 14.1.x, 15.1.x, and 16.1.x by causing an increase in memory resource utilization when an HTTP2 profile is configured on a virtual server.
How can I mitigate CVE-2022-35236?
To mitigate CVE-2022-35236, update your F5 BIG-IP software to version 16.1.2.2, 15.1.6.1, or 14.1.5.
What is the severity of CVE-2022-35236?
CVE-2022-35236 has a severity rating of 7.5 (High).
Where can I find more information about CVE-2022-35236?
You can find more information about CVE-2022-35236 on the F5 support website at: https://support.f5.com/csp/article/K79933541