F5-K000141003: High severity f5 big-ip access policy manager vulnerability
Published Feb 5, 2025
·Updated
When a BIG-IP APM access profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate.
Affected Software
3 affected componentsFixes available
F5 BIG-IP (APM)>=17.1.0<=17.1.1
17.1.2
F5 BIG-IP (APM)>=16.1.3<=16.1.4
16.1.5
F5 BIG-IP (APM)
Event History
Feb 5, 2025
Advisory Published
via F5·02:03 PM
Frequently Asked Questions
1
What is the severity of F5-K000141003?
The severity of F5-K000141003 is classified as critical due to potential disruptions in service caused by TMM termination.
2
How do I fix F5-K000141003?
To fix F5-K000141003, upgrade your BIG-IP APM system to version 16.1.5 or later.
3
What products are affected by F5-K000141003?
F5-K000141003 affects F5 BIG-IP APM versions between 16.1.3 and 16.1.4.
4
What can trigger the vulnerability F5-K000141003?
Undisclosed requests sent to a BIG-IP APM access profile on a configured virtual server can trigger F5-K000141003.
5
Is there a workaround for F5-K000141003?
There is no confirmed workaround for F5-K000141003 other than upgrading to the latest version.