First published: Wed Feb 01 2023(Updated: )
An open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy. This vulnerability allows an unauthenticated malicious attacker to build an open redirect URI.
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP Access Policy Manager | =17.0.0 | 17.1.0 |
F5 BIG-IP Access Policy Manager | >=16.1.0<=16.1.3 | 16.1.3.3 |
F5 BIG-IP Access Policy Manager | >=15.1.0<=15.1.6 | 15.1.7 |
F5 BIG-IP Access Policy Manager | >=14.1.0<=14.1.5 | 14.1.5.3 |
F5 BIG-IP Access Policy Manager | >=13.1.0<=13.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of F5-K95503300 is critical due to the potential for unauthorized redirection by attackers.
To fix F5-K95503300, you should upgrade your F5 BIG-IP (APM) to the latest patched version as specified in the advisory.
F5-K95503300 affects various versions of F5 BIG-IP (APM) including 17.1.0, 16.1.3.3, 15.1.7, and 14.1.5.3.
An attacker exploiting F5-K95503300 can create malicious open redirect URLs, potentially leading users to phishing sites.
No, F5-K95503300 can be exploited by unauthenticated attackers, increasing its risk.