F5-K000152614: High severity F5 BIG-IP vulnerability
Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000152614?
The F5-K000152614 vulnerability is classified as a denial-of-service (DoS) threat due to insufficient resource limits on multipart headers in Apache Commons FileUpload.
How do I fix F5-K000152614?
To address the F5-K000152614 vulnerability, users should upgrade Apache Commons FileUpload to version 1.6 or 2.0.0-M4.
Which software versions are affected by F5-K000152614?
F5-K000152614 affects F5 BIG-IP versions 17.5.0 to 17.5.1, 17.1.0 to 17.1.2, 16.1.0 to 16.1.6, and 15.1.0 to 15.1.10, as well as F5 Traffix SDC version 5.2.0.
What specific systems does F5-K000152614 impact?
F5-K000152614 impacts systems running affected versions of F5 BIG-IP and Traffix SDC due to vulnerabilities in the Apache Commons FileUpload component.
Is there a workaround for F5-K000152614?
Currently, the recommended solution for F5-K000152614 is to perform the upgrade to the secure versions rather than relying on a workaround.