PT-2013-2133 · F5 · Firepass+1
Neal Poole
·
Published
2013-08-09
·
Updated
2023-12-14
·
CVE-2013-0150
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
F5 BIG-IP APM versions 10.1.0 through 10.2.4
F5 BIG-IP APM versions 11.0.0 through 11.3.0
FirePass versions 6.0.0 through 6.1.0
FirePass version 7.0.0
Description
A directory traversal issue exists in the client-side components of the affected products when APM is provisioned. This allows remote attackers to upload and execute arbitrary files by including a .. (dot dot) in the
filename parameter.Recommendations
For F5 BIG-IP APM versions 10.1.0 through 10.2.4, update to a version outside of this range to resolve the issue.
For F5 BIG-IP APM versions 11.0.0 through 11.3.0, update to a version outside of this range to resolve the issue.
For FirePass versions 6.0.0 through 6.1.0, update to a version outside of this range to resolve the issue.
For FirePass version 7.0.0, update to a version later than 7.0.0 to resolve the issue.
As a temporary workaround, consider restricting access to the vulnerable
filename parameter in the affected products until a patch is available.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
F5 Big-Ip Apm
Firepass