F5 / Big-IP Websafe
175 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2017-6159 | F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1 are vulnerable to a d… | MEDIUM | 5.9 | Oct 27, 2017 |
| CVE-2017-6157 | In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 12.0.0 to 12.1.1, 11.6.0 to 11.6.1, 11.5.0 - 11.5.… | HIGH | 8.1 | Oct 27, 2017 |
| CVE-2017-0303 | In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 13.0.0, 12.0.0 to 12.1.2 and 11.5.1 to 11.6.1, und… | HIGH | 7.5 | Oct 27, 2017 |
| CVE-2017-6165 | In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, and WebSafe 11.5.1 HF6 through 11.5.4 HF4, 11.6.0 through 11.6.1 HF1, and 12.0… | CRITICAL | 9.8 | Oct 20, 2017 |
| CVE-2017-6145 | iControl REST in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe 12.0.0 through 12.1.2 and 13.0.0 includes a service to co… | HIGH | 7.3 | Oct 20, 2017 |
| CVE-2017-6141 | In F5 BIG-IP LTM, AAM, AFM, APM, ASM, Link Controller, PEM, and WebSafe 12.1.0 through 12.1.2, certain values in a TLS abbreviated handshake when using a clien… | MEDIUM | 5.9 | Oct 20, 2017 |
| CVE-2017-6147 | In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe 12.1.2-HF1 and 13.0.0, an undisclosed type of responses may cause TMM t… | MEDIUM | 5.9 | Sep 18, 2017 |
| CVE-2016-7469 | A stored cross-site scripting (XSS) vulnerability in the Configuration utility device name change page in BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge… | MEDIUM | 5.4 | Jun 9, 2017 |
| CVE-2017-6131 | In some circumstances, an F5 BIG-IP version 12.0.0 to 12.1.2 and 13.0.0 Azure cloud instance may contain a default administrative password which could be used… | CRITICAL | 9.8 | May 23, 2017 |
| CVE-2016-7476 | The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, AAM, AFM, APM, ASM, GTM, Link Controller, PEM, PSM, and WebSafe 11.6.0 before 11.6.0 HF6, 11.5.0 bef… | HIGH | 7.5 | May 11, 2017 |
| CVE-2016-9250 | In F5 BIG-IP 11.2.1, 11.4.0 through 11.6.1, and 12.0.0 through 12.1.2, an unauthenticated user with access to the control plane may be able to delete arbitrary… | HIGH | 7.5 | May 10, 2017 |
| CVE-2017-6137 | In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, PSM, WebAccelerator, and WebSafe 11.6.1 HF1, 12.0.0 HF3, 12.0.0… | MEDIUM | 5.9 | May 9, 2017 |
| CVE-2016-9256 | In F5 BIG-IP 12.1.0 through 12.1.2, permissions enforced by iControl can lag behind the actual permissions assigned to a user if the role_map is not reloaded b… | HIGH | 7.5 | May 9, 2017 |
| CVE-2016-9253 | In F5 BIG-IP 12.1.0 through 12.1.2, specific websocket traffic patterns may cause a disruption of service for virtual servers configured to use the websocket p… | HIGH | 7.5 | May 9, 2017 |
| CVE-2016-9251 | In F5 BIG-IP 12.0.0 through 12.1.2, an authenticated attacker may be able to cause an escalation of privileges through a crafted iControl REST connection. | HIGH | 8.8 | May 9, 2017 |
| CVE-2017-6128 | An attacker may be able to cause a denial-of-service (DoS) attack against the sshd component in F5 BIG-IP, Enterprise Manager, BIG-IQ, and iWorkflow. | HIGH | 7.5 | May 1, 2017 |
| CVE-2016-9252 | The Traffic Management Microkernel (TMM) in F5 BIG-IP before 11.5.4 HF3, 11.6.x before 11.6.1 HF2 and 12.x before 12.1.2 does not properly handle minimum path… | HIGH | 7.5 | Mar 27, 2017 |
| CVE-2016-7474 | In some cases the MCPD binary cache in F5 BIG-IP devices may allow a user with Advanced Shell access, or privileges to generate a qkview, to temporarily obtain… | MEDIUM | 5.5 | Mar 27, 2017 |
| CVE-2016-9245 | In F5 BIG-IP systems 12.1.0 - 12.1.2, malicious requests made to virtual servers with an HTTP profile can cause the TMM to restart. The issue is exposed with B… | MEDIUM | 5.9 | Mar 7, 2017 |
| CVE-2016-6249 | F5 BIG-IP 12.0.0 and 11.5.0 - 11.6.1 REST requests which timeout during user account authentication may log sensitive attributes such as passwords in plaintext… | MEDIUM | 5.3 | Feb 20, 2017 |
| CVE-2016-9249 | An undisclosed traffic pattern received by a BIG-IP Virtual Server with TCP Fast Open enabled may cause the Traffic Management Microkernel (TMM) to restart, re… | HIGH | 7.5 | Jan 31, 2017 |
| CVE-2016-9247 | Under certain conditions for BIG-IP systems using a virtual server with an associated FastL4 profile and TCP analytics profile, a specific sequence of packets… | MEDIUM | 5.9 | Jan 10, 2017 |
| CVE-2016-5700 | Virtual servers in F5 BIG-IP systems 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0 before HF4, an… | CRITICAL | 9.8 | Oct 3, 2016 |
| CVE-2016-5736 | The default configuration of the IPsec IKE peer listener in F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.1 before HF16, 11.4.x, 11.5.x before 1… | HIGH | 7.5 | Aug 19, 2016 |
| CVE-2015-8022 | The Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, and Link Controller 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x be… | HIGH | 7.5 | Aug 19, 2016 |
Showing 151 to 175 of 175 CVEs