PT-2013-2133 · F5 · Firepass+1

Neal Poole

·

Published

2013-08-09

·

Updated

2023-12-14

·

CVE-2013-0150

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions F5 BIG-IP APM versions 10.1.0 through 10.2.4 F5 BIG-IP APM versions 11.0.0 through 11.3.0 FirePass versions 6.0.0 through 6.1.0 FirePass version 7.0.0
Description A directory traversal issue exists in the client-side components of the affected products when APM is provisioned. This allows remote attackers to upload and execute arbitrary files by including a .. (dot dot) in the filename parameter.
Recommendations For F5 BIG-IP APM versions 10.1.0 through 10.2.4, update to a version outside of this range to resolve the issue. For F5 BIG-IP APM versions 11.0.0 through 11.3.0, update to a version outside of this range to resolve the issue. For FirePass versions 6.0.0 through 6.1.0, update to a version outside of this range to resolve the issue. For FirePass version 7.0.0, update to a version later than 7.0.0 to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable filename parameter in the affected products until a patch is available.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2013-0150

Affected Products

F5 Big-Ip Apm
Firepass