HIGH · 7.5

CVE-2015-8022

The Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, and Link Controller 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BI...

Vulnerability Description

The Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, and Link Controller 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP AAM 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP AFM and PEM 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP Edge Gateway, WebAccelerator, and WOM 11.x before 11.2.1 HF16 and 11.3.0; and BIG-IP PSM 11.x before 11.2.1 HF16, 11.3.x, and 11.4.x before 11.4.1 HF10 allows remote authenticated users with certain permissions to gain privileges by leveraging an Access Policy Manager customization configuration section that allows file uploads.

CVSS Score

7.5

HIGH

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
F5Big-Ip Global Traffic Manager11.0.0
F5Big-Ip Local Traffic Manager11.0.0
F5Big-Ip Webaccelerator11.0.0
F5Big-Ip Policy Enforcement Manager11.3.0
F5Big-Ip Advanced Firewall Manager11.3.0
F5Big-Ip Access Policy Manager11.0.0
F5Big-Ip Analytics11.0.0
F5Big-Ip Wan Optimization Manager11.0.0
F5Big-Ip Link Controller11.0.0
F5Big-Ip Edge Gateway11.0.0
F5Big-Ip Application Security Manager11.0.0
F5Big-Ip Application Acceleration Manager11.4.0
F5Big-Ip Websafe11.6.0
F5Big-Ip Protocol Security Module11.0.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-8022?

CVE-2015-8022 is a vulnerability with a CVSS score of 7.5 (HIGH). The Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, and Link Controller 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BI...

How severe is CVE-2015-8022?

CVE-2015-8022 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-8022?

Check the references section above for vendor advisories and patch information. Affected products include: F5 Big-Ip Global Traffic Manager, F5 Big-Ip Local Traffic Manager, F5 Big-Ip Webaccelerator, F5 Big-Ip Policy Enforcement Manager, F5 Big-Ip Advanced Firewall Manager.