Known vulnerabilities in BIG-IP Advanced WAF 12.1.5
Vendor:
F5 Networks
Software:
BIG-IP Advanced WAF
Version:
12.1.5
Software CPE:
cpe:2.3:a:f5_networks:big-ip_advanced_waf:*:*:*:*:*:*:*:*
Website:
https://f5.com/
Total vulnerabilities:
42
Public exploits:
10
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
17.5.0
17.1.2
17.1.1
17.1.0
15.1.10.7
15.1.10.6
15.1.10.5
15.1.10.4
15.1.10.3
15.1.10.2
15.1.10.1
15.1.10.0
17.5.1
15.1.10.8
17.1.3
14.1.4.2
13.1.0.8
14.1.4.5
15.1.4.1
16.1.2
14.1.4.4
15.1.4
16.1.1
14.1.4.1
12.1.6
16.1.0
13.1.4.1
14.1.4.3
15.1.3.1
16.0.1.2
13.1.4
15.1.3
11.6.5.3
12.1.5.3
14.1.4
13.1.3.6
15.1.2.1
16.0.1.1
14.1.3.1
13.1.3.4
13.1.3.5
14.1.3
15.1.2
16.0.1
15.1.1
14.1.2.8
13.0.0
12.1.2 HF1
14.0.0
13.0.0 HF3
12.1.2 HF2
11.6.2 HF1
15.1.0.2
14.1.2-0.89.37
14.1.2.5
12.1.5.2
11.6.1
11.6.2
11.6.3
11.6.4
11.6.5
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
12.1.5
13.1.0
13.1.1
13.1.3
14.1.0
14.1.2
15.0.0
15.0.1
15.1.0
16.0.0
Vulnerabilities (42)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU59846 - Unrestricted Upload of File with Dangerous Type CVE-2022-23026 |
CWE-434 | Medium | 14.1.4.5, 15.1.4.1, 16.1.2 | 19.01.2022 |
SB2022011950 |
||
| #VU56113 - Permissions, Privileges, and Access Controls CVE-2021-23031 |
CWE-264 | Medium | 11.6.5.3, 12.1.6, 13.1.4, 14.1.4.1, 15.1.3, 16.0.1.2, 16.1.0 | 26.08.2021 |
SB2021082612 |
||
| #VU56088 - Improper input validation CVE-2021-23045 |
CWE-20 | Low | 13.1.4.1, 14.1.4.3, 15.1.3.1, 16.0.1.2, 16.1.0 | 25.08.2021 |
SB2021082512 |
||
| #VU51496 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2021-22990 |
CWE-78 | Medium | 11.6.5.3, 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1 | 16.03.2021 |
SB2021031609 |
||
| #VU51495 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2021-22989 |
CWE-78 | Medium | 11.6.5.3, 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1 | 16.03.2021 |
SB2021031608 |
||
| #VU51494 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2021-22988 |
CWE-78 | High | 11.6.5.3, 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1 | 16.03.2021 |
SB2021031607 |
||
| #VU51493 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2021-22987 |
CWE-78 | High | 11.6.5.3, 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1 | 16.03.2021 |
SB2021031606 |
||
| #VU51492 - Memory corruption CVE-2021-22992 |
CWE-119 | High | 11.6.5.3, 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1 | 16.03.2021 |
SB2021031605 |
||
| #VU51491 - Resource Management Errors CVE-2021-23003 |
CWE-399 | Medium | 11.6.5.3, 12.1.5.3, 13.1.3.6, 14.1.3.1, 15.1.2, 16.0.1.1 | 16.03.2021 |
SB2021031604 |
||
| #VU51423 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2021-22994 |
CWE-79 | Medium | 11.6.5.3, 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1 | 11.03.2021 |
SB2021031121 |
||
| #VU51422 - Memory corruption CVE-2021-22991 |
CWE-119 | High | 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1 | 11.03.2021 |
SB2021031120 |
||
| #VU51421 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2021-22993 |
CWE-79 | Medium | 12.1.5.3, 13.1.3.6, 14.1.3.1, 15.1.2, 16.0.1.1 | 11.03.2021 |
SB2021031119 |
||
| #VU51418 - Resource exhaustion CVE-2021-23004 |
CWE-400 | Medium | 11.6.5.3, 12.1.5.3, 13.1.3.6, 14.1.3.1, 15.1.2, 16.0.1.1 | 11.03.2021 |
SB2021031116 |
||
| #VU51391 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2021-22986 |
CWE-78 | High | 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1 | 11.03.2021 |
SB2021031102 |
||
| #VU51269 - Exposure of sensitive information to an unauthorized actor CVE-2019-18282 |
CWE-200 | Medium | - | 09.03.2021 |
SB2020011633 SB2021030902 SB2021030903 and 5 more |
||
| #VU50780 - Memory corruption CVE-2020-8625 |
CWE-119 | High | - | 17.02.2021 |
SB2021021718 SB2021021908 SB2021022703 and 28 more |
||
| #VU50075 - Reachable Assertion CVE-2021-3326 |
CWE-617 | Medium | - | 27.01.2021 |
SB2021012804 SB2021020710 SB2021020711 and 34 more |
||
| #VU50329 - Out-of-bounds read CVE-2019-25013 |
CWE-125 | Low | - | 04.01.2021 |
SB2021020413 SB2021020414 SB2021020710 and 36 more |
||
| #VU48569 - Resource Management Errors CVE-2020-8277 |
CWE-399 | Medium | - | 19.11.2020 |
SB2020112003 SB2020112005 SB2020102133 and 23 more |
||
| #VU47106 - Out-of-bounds read CVE-2020-14314 |
CWE-125 | Low | - | 15.09.2020 |
SB2020092605 SB2020090877 SB2021031201 and 14 more |
Showing elements 1 - 20 out of 42