Directory traversal vulnerability in an unspecified signed Java applet in the client-side components in F5 BIG-IP APM 10.1.0 through 10.2.4 and 11.0.0 through 11.3.0, FirePass 6.0.0 through 6.1.0 and 7.0.0, and other products "when APM is provisioned," allows remote attackers to upload and execute arbitrary files via a .. (dot dot) in the filename parameter.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-09-16T18:29:34.115Z
Reserved: 2012-12-06T00:00:00Z
Link: CVE-2013-0150

No data.

Status : Deferred
Published: 2013-08-09T20:56:06.917
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-0150

No data.

No data.