CVE-2022-35245: BIG-IP APM access policy vulnerability CVE-2022-35245
In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5.1, when a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-35245?
CVE-2022-35245 is rated as a medium severity vulnerability due to its potential impact on system stability.
How do I fix CVE-2022-35245?
To fix CVE-2022-35245, upgrade your F5 BIG-IP Access Policy Manager to versions 14.1.5.1, 15.1.6.1, or 16.1.3.1 or later.
What versions of F5 BIG-IP Access Policy Manager are affected by CVE-2022-35245?
Affected versions of F5 BIG-IP Access Policy Manager include 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5.1.
What can happen if CVE-2022-35245 is exploited?
Exploitation of CVE-2022-35245 can lead to the termination of the Traffic Management Microkernel (TMM), affecting system availability.
Is there a specific configuration that exposes my system to CVE-2022-35245?
Yes, CVE-2022-35245 affects systems where a BIG-IP APM access policy is configured on a virtual server.