First published: Wed Feb 01 2023(Updated: )
Incorrect permission assignment vulnerabilities exist in the iControl REST and TMOS shell (tmsh) dig command which may allow an authenticated attacker with resource administrator role privilege to view sensitive information.
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP and BIG-IQ Centralized Management | =17.0.0 | 17.1.0 |
F5 BIG-IP and BIG-IQ Centralized Management | >=16.1.0<=16.1.3 | 16.1.3.3 |
F5 BIG-IP and BIG-IQ Centralized Management | >=15.1.0<=15.1.8 | 15.1.8.1 |
F5 BIG-IP and BIG-IQ Centralized Management | >=14.1.0<=14.1.5 | 14.1.5.3 |
F5 BIG-IP and BIG-IQ Centralized Management | >=13.1.0<=13.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability F5-K83284425 is classified as a medium severity issue due to its potential for exposing sensitive information.
To fix F5-K83284425, upgrade to the appropriate patched version of the F5 BIG-IP software as specified in the advisory.
F5-K83284425 affects authenticated users with resource administrator role privilege on specific versions of F5 BIG-IP.
F5-K83284425 may allow the exposure of sensitive information accessible to users with limited access rights.
Currently, the advised mitigation for F5-K83284425 is to apply the necessary patches rather than relying on workarounds.