PT-2025-42321 · F5 · Big-Ip

Published

2025-10-15

·

Updated

2025-10-21

·

CVE-2025-47148

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions BIG-IP versions (affected versions not specified)
Description The BIG-IP system, when configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP) with single logout (SLO) enabled on an access policy, may experience increased memory resource utilization due to undisclosed requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-47148

Affected Products

Big-Ip