PT-2021-15375 · F5 · F5 Big-Ip
Published
2021-09-14
·
Updated
2021-09-27
·
CVE-2021-23052
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
F5 BIG-IP versions 13.1.x and earlier
F5 BIG-IP versions 14.1.x through 14.1.4.3
Description
An open redirect issue exists on virtual servers enabled with a BIG-IP APM access policy, allowing an unauthenticated malicious user to build an open redirect URI.
Recommendations
For versions 13.1.x, update to a version that is still supported to mitigate the risk.
For versions 14.1.x through 14.1.4.3, update to version 14.1.4.4 or later.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
F5 Big-Ip