F5-K000136909: Medium severity f5 big-ip access policy manager vulnerability
Published Sep 27, 2023
·Updated
BIG-IP APM clients may send IP traffic outside of the VPN tunnel.
Affected Software
10 affected componentsFixes available
F5 BIG-IP APM>=17.1.0<=17.1.1
17.1.1.13
F5 BIG-IP APM>=16.1.3.3<=16.1.4
16.1.4.23
F5 BIG-IP APM>=15.1.8<=15.1.10
15.1.10.33
F5 BIG-IP APM>=14.1.5.2<=14.1.5.6
F5 BIG-IP APM=13.1.5.1
F5 APM Clients>=7.2.3<=7.2.4
7.2.4.63
F5 F5 Access for Android=3.0.9
F5 F5 Access for iOS=3.0.13
3.1.03
F5 F5 Access for macOS=2.0.2
F5 F5 Access for Windows>=1.2<=1.3
Event History
Sep 27, 2023
Advisory Published
via F5·02:01 PM
Frequently Asked Questions
1
What is the severity of F5-K000136909?
The severity of F5-K000136909 can vary based on the environment and usage but typically is tagged as critical due to potential data leakage risks.
2
How do I fix F5-K000136909?
To fix F5-K000136909, update your BIG-IP APM and related clients to the recommended versions provided by F5.
3
What versions are affected by F5-K000136909?
F5-K000136909 affects several versions of BIG-IP APM ranging from 13.1.5.1 to 17.1.1.13 and multiple related F5 Access clients.
4
What impact does F5-K000136909 have on users?
F5-K000136909 can allow users to send IP traffic outside of the VPN tunnel, risking exposure of sensitive data.
5
Is it necessary to patch for F5-K000136909?
Yes, patching for F5-K000136909 is crucial to maintain the security and integrity of your network traffic.