A directory traversal vulnerability exists in TMUI that allows an authenticated attacker to access files which are not limited to the intended files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as expression or command delimiters when they are sent to a downstream component.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Big-ip_access_policy_manager | F5 | 15.1.0 (including) | 15.1.10.8 (excluding) |
| Big-ip_advanced_firewall_manager | F5 | 15.1.0 (including) | 15.1.10.8 (excluding) |
| Big-ip_advanced_web_application_firewall | F5 | 15.1.0 (including) | 15.1.10.8 (excluding) |
| Big-ip_analytics | F5 | 15.1.0 (including) | 15.1.10.8 (excluding) |
| Big-ip_application_acceleration_manager | F5 | 15.1.0 (including) | 15.1.10.8 (excluding) |
| Big-ip_application_security_manager | F5 | 15.1.0 (including) | 15.1.10.8 (excluding) |
| Big-ip_application_visibility_and_reporting | F5 | 15.1.0 (including) | 15.1.10.8 (excluding) |
| Big-ip_automation_toolchain | F5 | 15.1.0 (including) | 15.1.10.8 (excluding) |
| Big-ip_carrier-grade_nat | F5 | 15.1.0 (including) | 15.1.10.8 (excluding) |
| Big-ip_container_ingress_services | F5 | 15.1.0 (including) | 15.1.10.8 (excluding) |
| Big-ip_ddos_hybrid_defender | F5 | 15.1.0 (including) | 15.1.10.8 (excluding) |
| Big-ip_domain_name_system | F5 | 15.1.0 (including) | 15.1.10.8 (excluding) |
| Big-ip_edge_gateway | F5 | 15.1.0 (including) | 15.1.10.8 (excluding) |
| Big-ip_fraud_protection_service | F5 | 15.1.0 (including) | 15.1.10.8 (excluding) |
| Big-ip_global_traffic_manager | F5 | 15.1.0 (including) | 15.1.10.8 (excluding) |
| Big-ip_link_controller | F5 | 15.1.0 (including) | 15.1.10.8 (excluding) |
| Big-ip_local_traffic_manager | F5 | 15.1.0 (including) | 15.1.10.8 (excluding) |
| Big-ip_policy_enforcement_manager | F5 | 15.1.0 (including) | 15.1.10.8 (excluding) |
| Big-ip_ssl_orchestrator | F5 | 15.1.0 (including) | 15.1.10.8 (excluding) |
| Big-ip_webaccelerator | F5 | 15.1.0 (including) | 15.1.10.8 (excluding) |
| Big-ip_websafe | F5 | 15.1.0 (including) | 15.1.10.8 (excluding) |