F5-K000136907: Medium severity f5 big-ip access policy manager vulnerability
Published Sep 27, 2023
·Updated
BIG-IP APM clients may send IP traffic outside of the VPN tunnel.
Affected Software
9 affected componentsFixes available
F5 BIG-IP APM>=17.1.0<=17.1.1
3
F5 BIG-IP APM=16.1.3.3
3
F5 BIG-IP APM=15.1.8
3
F5 BIG-IP APM>=14.1.5.2<=14.1.5.6
3
F5 BIG-IP APM=13.1.5.1
3
F5 APM Clients>=7.2.3<=7.2.4
7.2.4.6
F5 F5 Access for iOS>=3.0.13<=3.0.14
F5 F5 Access for macOS>=2.0.2<=2.0.3
F5 F5 Access for Windows>=1.2<=1.3
Event History
Sep 27, 2023
Advisory Published
via F5·02:05 PM
Frequently Asked Questions
1
What is the severity of F5-K000136907?
The severity of F5-K000136907 is rated as critical.
2
How do I fix F5-K000136907?
To fix F5-K000136907, you should upgrade to the latest patched version of BIG-IP APM or the affected F5 Access clients.
3
Which versions are affected by F5-K000136907?
F5-K000136907 affects multiple versions of BIG-IP APM ranging from 13.1.5.1 to 17.1.1 and specific versions of F5 Access clients for iOS, macOS, and Windows.
4
What does F5-K000136907 indicate about VPN traffic?
F5-K000136907 indicates that clients may unintentionally send IP traffic outside of the established VPN tunnel.
5
Is authentication affected by F5-K000136907?
F5-K000136907 primarily concerns IP traffic routing issues and does not directly affect authentication processes.