On BIG-IP FPS, ASM, and Advanced WAF versions 16.1.x before 16.1.1, 15.1.x before 15.1.4, and 14.1.x before 14.1.4.4, an XML External Entity (XXE) vulnerability exists in an undisclosed page of the F5 Advanced Web Application Firewall (Advanced WAF) and BIG-IP ASM Traffic Management User Interface (TMUI), also referred to as the Configuration utility, that allows an authenticated high-privileged attacker to read local files and force BIG-IP to send HTTP requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://support.f5.com/csp/article/K61112120 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: f5
Published: 2022-01-25T19:11:33
Updated: 2024-08-03T03:28:43.238Z
Reserved: 2022-01-10T00:00:00
Link: CVE-2022-23031
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-01-25T20:15:10.007
Modified: 2024-11-21T06:47:50.727
Link: CVE-2022-23031
Redhat
No data.