PT-2016-3848 · F5 · F5 Big-Ip Edge Gateway+8

Published

2016-04-12

·

Updated

2016-11-28

·

CVE-2015-8021

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions F5 BIG-IP LTM, Analytics, APM, ASM, GTM, Link Controller, and PSM versions 11.x through 11.2.1 before HF11, 11.3.x, 11.4.0 through 11.4.0 before HF8, and 11.4.1 through 11.4.1 before HF6 F5 BIG-IP AAM versions 11.4.0 through 11.4.0 before HF8, and 11.4.1 through 11.4.1 before HF6 F5 BIG-IP AFM and PEM versions 11.3.x, 11.4.0 through 11.4.0 before HF8, and 11.4.1 through 11.4.1 before HF6 F5 BIG-IP Edge Gateway, WebAccelerator, and WOM versions 11.x through 11.2.1 before HF11, and 11.3.0
Description The issue allows remote authenticated users to upload files via the uploadImage.php endpoint. This is due to an incomplete blacklist vulnerability in the Configuration utility.
Recommendations For F5 BIG-IP LTM, Analytics, APM, ASM, GTM, Link Controller, and PSM versions 11.x through 11.2.1 before HF11, 11.3.x, 11.4.0 through 11.4.0 before HF8, and 11.4.1 through 11.4.1 before HF6, update to a version that includes the fix, such as 11.2.1 HF11 or later, 11.4.0 HF8 or later, and 11.4.1 HF6 or later. For F5 BIG-IP AAM versions 11.4.0 through 11.4.0 before HF8, and 11.4.1 through 11.4.1 before HF6, update to a version that includes the fix, such as 11.4.0 HF8 or later, and 11.4.1 HF6 or later. For F5 BIG-IP AFM and PEM versions 11.3.x, 11.4.0 through 11.4.0 before HF8, and 11.4.1 through 11.4.1 before HF6, update to a version that includes the fix, such as 11.4.0 HF8 or later, and 11.4.1 HF6 or later. For F5 BIG-IP Edge Gateway, WebAccelerator, and WOM versions 11.x through 11.2.1 before HF11, and 11.3.0, update to a version that includes the fix, such as 11.2.1 HF11 or later. As a temporary workaround, consider restricting access to the uploadImage.php endpoint until a patch is available.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-8021

Affected Products

F5 Big-Ip Apm
F5 Big-Ip Analytics
F5 Big-Ip Edge Gateway
F5 Big-Ip Gtm
F5 Big-Ip Ltm
F5 Big-Ip Link Controller
F5 Big-Ip Pem
F5 Big-Ip Wom
F5 Big-Ip Webaccelerator