CVE Vulnerabilities

CVE-2015-8022

Published: Aug 19, 2016 | Modified: Jun 06, 2019
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
8.5 HIGH
AV:N/AC:M/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, and Link Controller 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP AAM 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP AFM and PEM 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP Edge Gateway, WebAccelerator, and WOM 11.x before 11.2.1 HF16 and 11.3.0; and BIG-IP PSM 11.x before 11.2.1 HF16, 11.3.x, and 11.4.x before 11.4.1 HF10 allows remote authenticated users with certain permissions to gain privileges by leveraging an Access Policy Manager customization configuration section that allows file uploads.

Affected Software

Name Vendor Start Version End Version
Big-ip_global_traffic_manager F5 11.0.0 (including) 11.0.0 (including)
Big-ip_global_traffic_manager F5 11.1.0 (including) 11.1.0 (including)
Big-ip_global_traffic_manager F5 11.2.0 (including) 11.2.0 (including)
Big-ip_global_traffic_manager F5 11.2.1 (including) 11.2.1 (including)
Big-ip_global_traffic_manager F5 11.3.0 (including) 11.3.0 (including)
Big-ip_global_traffic_manager F5 11.4.0 (including) 11.4.0 (including)
Big-ip_global_traffic_manager F5 11.4.1 (including) 11.4.1 (including)
Big-ip_global_traffic_manager F5 11.5.0 (including) 11.5.0 (including)
Big-ip_global_traffic_manager F5 11.5.1 (including) 11.5.1 (including)
Big-ip_global_traffic_manager F5 11.5.2 (including) 11.5.2 (including)
Big-ip_global_traffic_manager F5 11.5.3 (including) 11.5.3 (including)
Big-ip_global_traffic_manager F5 11.6.0 (including) 11.6.0 (including)

References