MEDIUM
Incomplete blacklist vulnerability in the Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, Link Controller, and PSM 11.x before 11.2.1 HF11, 11.3.x, 11.4.0 before HF8, and 11.4.1 before HF6; BIG-IP AAM 11.4.0 before HF8 and 11.4.1 before HF6; BIG-IP AFM and PEM 11.3.x, 11.4.0 before HF8, and 11.4.1 before HF6; and BIG-IP Edge Gateway, WebAccelerator, and WOM 11.x before 11.2.1 HF11 and 11.3.0 allows remote authenticated users to upload files via uploadImage.php
Published Apr 12, 2016
4.3
MEDIUMCVSS 3.0
EPSS 1.35%
Description
Incomplete blacklist vulnerability in the Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, Link Controller, and PSM 11.x before 11.2.1 HF11, 11.3.x, 11.4.0 before HF8, and 11.4.1 before HF6; BIG-IP AAM 11.4.0 before HF8 and 11.4.1 before HF6; BIG-IP AFM and PEM 11.3.x, 11.4.0 before HF8, and 11.4.1 before HF6; and BIG-IP Edge Gateway, WebAccelerator, and WOM 11.x before 11.2.1 HF11 and 11.3.0 allows remote authenticated users to upload files via uploadImage.php.
Affected products
No data.
OR
- 11.0.0
- 11.1.0
- 11.2.0
- 11.2.1
- 11.3.0
- 11.4.0
- 11.4.1
- 11.3.0
- 11.4.0
- 11.4.1
- 11.0.0
- 11.1.0
- 11.2.0
- 11.2.1
- 11.3.0
- 11.4.0
- 11.4.1
- 11.4.0
- 11.4.1
- 11.0.0
- 11.1.0
- 11.2.0
- 11.2.1
- 11.3.0
- 11.4.0
- 11.4.1
- 11.0.0
- 11.1.0
- 11.2.0
- 11.2.1
- 11.3.0
- 11.0.0
- 11.1.0
- 11.2.0
- 11.2.1
- 11.3.0
- 11.4.0
- 11.0.0
- 11.1.0
- 11.2.0
- 11.2.1
- 11.3.0
- 11.4.0
- 11.4.1
- 11.0.0
- 11.1.0
- 11.2.0
- 11.2.1
- 11.3.0
- 11.4.0
- 11.4.1
- 11.3.0
- 11.4.0
- 11.4.1
- 11.0.0
- 11.1.0
- 11.2.0
- 11.2.1
- 11.3.0
- 11.4.0
- 11.4.1
- 11.0.0
- 11.1.0
- 11.2.0
- 11.2.1
- 11.3.0
- 11.0.0
- 11.1.0
- 11.2.0
- 11.2.1
- 11.3.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- http://www.securityfocus.com/bid/82340 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1034781 vdb-entryx_refsource_SECTRACK
- https://support.f5.com/kb/en-us/solutions/public/k/49/sol49580002.html x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/82340 | vdb-entryx_refsource_BID | |
| http://www.securitytracker.com/id/1034781 | vdb-entryx_refsource_SECTRACK | |
| https://support.f5.com/kb/en-us/solutions/public/k/49/sol49580002.html | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 12, 2016
Updated Aug 6, 2024
Reserved Oct 28, 2015
Link CVE-2015-8021
CISA Vulnrichment
Updated n/a