Known vulnerabilities in BIG-IP APM 15.0.1.0.48.11-ENG Hotfix
Vendor:
F5 Networks
Software:
BIG-IP APM
Version:
15.0.1.0.48.11-ENG Hotfix
Software CPE:
cpe:2.3:h:f5_networks:big-ip_apm:*:*:*:*:*:*:*:*
Website:
https://f5.com/
Total vulnerabilities:
27
Public exploits:
1
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
12.1.3.3
13.1.3.3
13.1.1.4
13.1.1.3
13.1.1.1
13.1.0.7
13.1.0.5
13.1.0.4
14.1.2.2
15.1.10.8
17.5.1
17.5.0
17.1.3.1
17.5.1.3
17.1.3
16.1.6.1
16.1.6
17.1.2.2
17.1.2.1
15.1.10.6.0.11.6
17.1.2
17.1.0.3
17.1.0.2
17.1.0.1
16.1.5
16.1.4.3
16.1.4.1
16.1.4
16.1.3.5
16.1.3.4
16.1.2.1
15.1.10
15.1.9.1
15.1.9
15.1.8.2
15.1.8.1
15.1.8
15.1.0.3
15.1.10.3
16.1.4.2
17.1.1
17.1.03
15.1.0
17.1.0
14.1.5.2
16.1.3.2
17.0.0.1
15.1.7
16.1.3.3
17.0.0.2
14.1.5.3
14.1.5
15.1.6
16.1.3
14.1.5.1
15.1.6.1
16.1.3.1
17.0.0
13.1.5
14.1.4.6
15.1.5.1
16.1.2.2
15.1.5
14.1.4.5
16.1.1
15.1.4.1
16.1.2
15.1.4
14.1.4.4
16.1.0
13.1.4.1
14.1.4.3
15.1.3.1
16.0.1.2
14.1.4.1
12.1.6
13.1.4
15.1.3
13.1.3.6 2
14.1.4 2
15.1.2.1 2
16.0.1.1 2
11.6.5.3
12.1.5.3
14.1.4
13.1.3.6
15.1.2.1
16.0.1.1
13.1.3.1
14.1.3.1
14.1.2.8
13.1.3.5
14.1.3
16.0.1
15.1.2
15.1.1
13.0.0 HF3
12.1.2 HF2
11.6.2 HF1
14.1.2.7
15.1.0.5
16.0.0
14.1.2-0.89.37
14.1.2.5
15.0.1.4
15.1.0.4
14.1.2.6
13.1.3.4
12.1.5.2
11.6.5.2
14.1.2.4
15.0.1.3
15.0.1.2
15.1.0.2
15.1.0.1
14.1.2.3
12.1.5.1
13.1.3.2
15.0.1.1
14.1.0.6
14.0.0.5
11.6.5.1
11.5.7
11.5.8
11.5.9
11.5.10
11.6.5
12.1.4
12.1.5
15.0.1
15.1.0
15.0.0
14.1.2.1.0.122.4-ENG Hotfix
14.1.2.1.0.115.4-ENG Hotfix
14.1.2.1.0.111.4-ENG Hotfix
14.1.2.1.0.105.4-ENG Hotfix
14.1.2.1.0.99.4-ENG Hotfix
14.1.2.1.0.97.4-ENG Hotfix
14.1.2.1.0.34.4-ENG Hotfix
14.1.2.1.0.16.4-ENG Hotfix
14.1.2.1.0.14.4-ENG Hotfix
14.1.2.1.0.46.4-ENG Hotfix
14.1.2.0.32.37-ENG Hotfix
14.1.2.0.18.37-ENG Hotfix
14.1.2.0.11.37-ENG Hotfix
14.1.0.6.0.70.9-ENG Hotfix
14.1.0.6.0.68.9-ENG Hotfix
14.1.0.6.0.14.9-ENG Hotfix
14.1.0.6.0.11.9-ENG Hotfix
14.1.0.5.0.40.5-ENG Hotfix
14.1.0.5.0.36.5-ENG Hotfix
14.1.0.5.0.15.5-ENG Hotfix
14.1.0.3.0.99.6-ENG Hotfix
14.1.0.3.0.97.6-ENG Hotfix
14.1.0.3.0.79.6-ENG Hotfix
15.0.1.0.48.11-ENG Hotfix
15.0.1.0.33.11-ENG Hotfix
13.1.1.5
14.1.2
14.1.1
14.0.1.1
14.1.2.1
13.1.3
11.6.4
14.1.0
14.0.1
14.0.0
13.1.1.2
7.1.6.1
7.1.7.1
7.1.7
7.1.6
13.1.1
13.1.0.8
12.1.3.2
12.1.3.4
13.1.0.6
11.6.3
12.1.3.1
13.0.1
11.5.6
11.5.5
11.5.4 HF4
12.1.3
13.1.0.3
13.1.0.2
13.1.0.1
13.1.0
11.5.3
11.5.2
11.5.1
11.5.0
11.6.2
11.4.0
11.2.1
11.5.4
11.5.1 HF6
11.6.0
12.0.1
12.1.2 HF1
13.0.0
12.1.0 HF1
12.0 HF4
12.0 HF3
12.0 HF1
12.1.2
12.0.0
11.6.1 HF1
12.1.1
12.1.0
11.6.1
Vulnerabilities (27)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU124687 - Improper input validation CVE-2025-53521 |
CWE-20 | Critical | 15.1.10.8, 16.1.6.1, 17.1.3, 17.5.1.3 | 30.03.2026 |
SB2025101655 |
||
| #VU103718 - Missing Support for Integrity Check CVE-2025-23415 |
CWE-353 | Low | 15.1.10.6.0.11.6, 16.1.5, 17.1.2 | 07.02.2025 |
SB2025020735 |
||
| #VU94063 - Use of a Broken or Risky Cryptographic Algorithm CVE-2024-3596 |
CWE-327 | Medium | - | 10.07.2024 |
SB2024071018 SB2024071019 SB2024071020 and 114 more |
||
| #VU56088 - Improper input validation CVE-2021-23045 |
CWE-20 | Low | 13.1.4.1, 14.1.4.3, 15.1.3.1, 16.0.1.2, 16.1.0 | 25.08.2021 |
SB2021082512 |
||
| #VU52738 - Improper Authentication CVE-2021-23008 |
CWE-287 | High | 12.1.6, 13.1.4, 14.1.4, 15.1.3 | 29.04.2021 |
SB2021042905 |
||
| #VU51419 - Resource exhaustion CVE-2021-22998 |
CWE-400 | Medium | 11.6.5.3, 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1 | 11.03.2021 |
SB2021031117 |
||
| #VU51394 - Resource Management Errors CVE-2021-22999 |
CWE-399 | Medium | 14.1.4, 15.1.0 | 11.03.2021 |
SB2021031104 |
||
| #VU50608 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2021-22979 |
CWE-79 | Medium | 13.1.3.5, 14.1.2.8, 15.1.1, 16.0.1 | 11.02.2021 |
SB2021021105 |
||
| #VU49083 - Resource exhaustion CVE-2020-27722 |
CWE-400 | Low | 13.1.3.5, 14.1.3.1, 15.0.1.4 | 17.12.2020 |
SB2020121737 |
||
| #VU49081 - Improper input validation CVE-2020-27716 |
CWE-20 | Medium | 14.1.3.1, 15.1.1 | 17.12.2020 |
SB2020121735 |
||
| #VU49080 - Improper input validation CVE-2020-27727 |
CWE-20 | Low | 13.1.3.5, 14.1.3.1, 15.1.1, 16.0.1.1 | 17.12.2020 |
SB2020121734 |
||
| #VU49079 - Resource Management Errors CVE-2020-27723 |
CWE-399 | Medium | 13.1.3.5, 14.1.3.1, 15.1.0 | 17.12.2020 |
SB2020121733 |
||
| #VU49078 - Resource exhaustion CVE-2020-27715 |
CWE-400 | Medium | 14.1.3.1, 15.1.1 | 17.12.2020 |
SB2020121731 |
||
| #VU49069 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2020-27726 |
CWE-79 | Low | 13.1.3.5, 14.1.3.1, 15.1.1, 16.0.1 | 17.12.2020 |
SB2020121725 |
||
| #VU49067 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2020-27719 |
CWE-79 | Low | 14.1.3.1, 15.1.1, 16.0.1 | 17.12.2020 |
SB2020121723 |
||
| #VU49065 - Resource exhaustion CVE-2020-27724 |
CWE-400 | Medium | 13.1.3.5, 14.1.3.1, 15.0.1.4, 15.1.0.5, 16.0.1 | 17.12.2020 |
SB2020121721 |
||
| #VU49058 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2020-5948 |
CWE-79 | Medium | 13.1.3.5, 14.1.2.8, 15.1.1, 16.0.1 | 11.12.2020 |
SB2020121719 |
||
| #VU18254 - Out-of-bounds write CVE-2019-3863 |
CWE-787 | Medium | - | 15.04.2019 |
SB2019031904 SB2019041501 SB2019032002 and 20 more |
||
| #VU18025 - Integer overflow CVE-2019-3857 |
CWE-190 | Medium | - | 19.03.2019 |
SB2019031904 SB2019041501 SB2019032002 and 20 more |
||
| #VU18023 - Integer overflow CVE-2019-3856 |
CWE-190 | Medium | - | 19.03.2019 |
SB2019031904 SB2019041501 SB2019032002 and 20 more |
Showing elements 1 - 20 out of 27