Description
On F5 BIG-IP AFM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, an authenticated attacker with high privileges can upload a maliciously crafted file to the BIG-IP AFM Configuration utility, which allows an attacker to run arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-33137 | On F5 BIG-IP AFM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, an authenticated attacker with high privileges can upload a maliciously crafted file to the BIG-IP AFM Configuration utility, which allows an attacker to run arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated |
References
| Link | Providers |
|---|---|
| https://support.f5.com/csp/article/K08510472 |
|
History
No history.
Status: PUBLISHED
Assigner: f5
Published:
Updated: 2024-09-17T02:31:19.942Z
Reserved: 2022-04-19T00:00:00.000Z
Link: CVE-2022-28695
No data.
Status : Modified
Published: 2022-05-05T17:15:14.270
Modified: 2024-11-21T06:57:45.350
Link: CVE-2022-28695
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD