F5-K20717585: High severity f5 big-ip access policy manager vulnerability
Published Feb 1, 2023
·Updated
When the BIG-IP APM system is configured with all the following elements, undisclosed requests may cause the Traffic Management Microkernel (TMM) to terminate:
Affected Software
3 affected componentsFixes available
F5 BIG-IP APM
F5 BIG-IP APM>=14.1.0<=14.1.5
14.1.5.3
F5 BIG-IP APM>=13.1.0<=13.1.5
Event History
Feb 1, 2023
Advisory Published
via F5·01:05 PM
Frequently Asked Questions
1
What is the severity of F5-K20717585?
The severity of F5-K20717585 is high due to the potential for Traffic Management Microkernel termination.
2
How do I fix F5-K20717585?
To fix F5-K20717585, upgrade your F5 BIG-IP APM to the latest recommended version beyond the affected releases.
3
What versions of F5 BIG-IP APM are affected by F5-K20717585?
F5-K20717585 affects F5 BIG-IP APM versions 13.1.0 through 13.1.5 and 14.1.0 through 14.1.5.
4
What types of configurations trigger the vulnerability in F5-K20717585?
The vulnerability in F5-K20717585 is triggered by specific undisclosed request configurations on the BIG-IP APM system.
5
Can the vulnerability in F5-K20717585 be exploited remotely?
Yes, the vulnerability in F5-K20717585 may allow for remote exploitation under certain conditions.