Known vulnerabilities in BIG-IP APM 15.1.0
Vendor:
F5 Networks
Software:
BIG-IP APM
Version:
15.1.0
Software CPE:
cpe:2.3:h:f5_networks:big-ip_apm:*:*:*:*:*:*:*:*
Website:
https://f5.com/
Total vulnerabilities:
86
Public exploits:
10
Known exploited (KEV):
4
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
12.1.3.3
13.1.3.3
13.1.1.4
13.1.1.3
13.1.1.1
13.1.0.7
13.1.0.5
13.1.0.4
14.1.2.2
15.1.10.8
17.5.1
17.5.0
17.1.3.1
17.5.1.3
17.1.3
16.1.6.1
16.1.6
17.1.2.2
17.1.2.1
15.1.10.6.0.11.6
17.1.2
17.1.0.3
17.1.0.2
17.1.0.1
16.1.5
16.1.4.3
16.1.4.1
16.1.4
16.1.3.5
16.1.3.4
16.1.2.1
15.1.10
15.1.9.1
15.1.9
15.1.8.2
15.1.8.1
15.1.8
15.1.0.3
15.1.10.3
16.1.4.2
17.1.1
17.1.03
15.1.0
17.1.0
14.1.5.2
16.1.3.2
17.0.0.1
15.1.7
16.1.3.3
17.0.0.2
14.1.5.3
14.1.5
15.1.6
16.1.3
14.1.5.1
15.1.6.1
16.1.3.1
17.0.0
13.1.5
14.1.4.6
15.1.5.1
16.1.2.2
15.1.5
14.1.4.5
16.1.1
15.1.4.1
16.1.2
15.1.4
14.1.4.4
16.1.0
13.1.4.1
14.1.4.3
15.1.3.1
16.0.1.2
14.1.4.1
12.1.6
13.1.4
15.1.3
13.1.3.6 2
14.1.4 2
15.1.2.1 2
16.0.1.1 2
11.6.5.3
12.1.5.3
14.1.4
13.1.3.6
15.1.2.1
16.0.1.1
13.1.3.1
14.1.3.1
14.1.2.8
13.1.3.5
14.1.3
16.0.1
15.1.2
15.1.1
13.0.0 HF3
12.1.2 HF2
11.6.2 HF1
14.1.2.7
15.1.0.5
16.0.0
14.1.2-0.89.37
14.1.2.5
15.0.1.4
15.1.0.4
14.1.2.6
13.1.3.4
12.1.5.2
11.6.5.2
14.1.2.4
15.0.1.3
15.0.1.2
15.1.0.2
15.1.0.1
14.1.2.3
12.1.5.1
13.1.3.2
15.0.1.1
14.1.0.6
14.0.0.5
11.6.5.1
11.5.7
11.5.8
11.5.9
11.5.10
11.6.5
12.1.4
12.1.5
15.0.1
15.1.0
15.0.0
14.1.2.1.0.122.4-ENG Hotfix
14.1.2.1.0.115.4-ENG Hotfix
14.1.2.1.0.111.4-ENG Hotfix
14.1.2.1.0.105.4-ENG Hotfix
14.1.2.1.0.99.4-ENG Hotfix
14.1.2.1.0.97.4-ENG Hotfix
14.1.2.1.0.34.4-ENG Hotfix
14.1.2.1.0.16.4-ENG Hotfix
14.1.2.1.0.14.4-ENG Hotfix
14.1.2.1.0.46.4-ENG Hotfix
14.1.2.0.32.37-ENG Hotfix
14.1.2.0.18.37-ENG Hotfix
14.1.2.0.11.37-ENG Hotfix
14.1.0.6.0.70.9-ENG Hotfix
14.1.0.6.0.68.9-ENG Hotfix
14.1.0.6.0.14.9-ENG Hotfix
14.1.0.6.0.11.9-ENG Hotfix
14.1.0.5.0.40.5-ENG Hotfix
14.1.0.5.0.36.5-ENG Hotfix
14.1.0.5.0.15.5-ENG Hotfix
14.1.0.3.0.99.6-ENG Hotfix
14.1.0.3.0.97.6-ENG Hotfix
14.1.0.3.0.79.6-ENG Hotfix
15.0.1.0.48.11-ENG Hotfix
15.0.1.0.33.11-ENG Hotfix
13.1.1.5
14.1.2
14.1.1
14.0.1.1
14.1.2.1
13.1.3
11.6.4
14.1.0
14.0.1
14.0.0
13.1.1.2
7.1.6.1
7.1.7.1
7.1.7
7.1.6
13.1.1
13.1.0.8
12.1.3.2
12.1.3.4
13.1.0.6
11.6.3
12.1.3.1
13.0.1
11.5.6
11.5.5
11.5.4 HF4
12.1.3
13.1.0.3
13.1.0.2
13.1.0.1
13.1.0
11.5.3
11.5.2
11.5.1
11.5.0
11.6.2
11.4.0
11.2.1
11.5.4
11.5.1 HF6
11.6.0
12.0.1
12.1.2 HF1
13.0.0
12.1.0 HF1
12.0 HF4
12.0 HF3
12.0 HF1
12.1.2
12.0.0
11.6.1 HF1
12.1.1
12.1.0
11.6.1
Vulnerabilities (86)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU124687 - Improper input validation CVE-2025-53521 |
CWE-20 | Critical | 15.1.10.8, 16.1.6.1, 17.1.3, 17.5.1.3 | 30.03.2026 |
SB2025101655 |
||
| #VU103718 - Missing Support for Integrity Check CVE-2025-23415 |
CWE-353 | Low | 15.1.10.6.0.11.6, 16.1.5, 17.1.2 | 07.02.2025 |
SB2025020735 |
||
| #VU94063 - Use of a Broken or Risky Cryptographic Algorithm CVE-2024-3596 |
CWE-327 | Medium | - | 10.07.2024 |
SB2024071018 SB2024071019 SB2024071020 and 114 more |
||
| #VU76420 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2023-22372 |
CWE-300 | Medium | - | 23.05.2023 |
SB2023052307 |
||
| #VU71810 - URL Redirection to Untrusted Site ('Open Redirect') CVE-2023-22418 |
CWE-601 | Low | 14.1.5.3, 15.1.7, 16.1.3.3, 17.0.0.2 | 06.02.2023 |
SB2023020617 |
||
| #VU66139 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2022-31473 |
CWE-22 | Low | 15.1.4, 16.1.1, 17.0.0 | 05.08.2022 |
SB2022080534 |
||
| #VU66100 - Resource exhaustion CVE-2022-33203 |
CWE-400 | Medium | 14.1.5, 15.1.6.1, 16.1.3 | 04.08.2022 |
SB2022080421 |
||
| #VU66097 - NULL Pointer Dereference CVE-2022-35245 |
CWE-476 | Medium | 14.1.5.1, 15.1.6.1, 16.1.3.1 | 04.08.2022 |
SB2022080419 |
||
| #VU59886 - Origin Validation Error CVE-2022-23032 |
CWE-346 | Low | 14.1.4.5 | 20.01.2022 |
SB2022012022 |
||
| #VU59880 - Improper input validation CVE-2022-23014 |
CWE-20 | Medium | 15.1.4.1, 16.1.2 | 20.01.2022 |
SB2022012016 |
||
| #VU56903 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2021-23054 |
CWE-79 | Medium | 14.1.4.4, 15.1.4, 16.1.0 | 28.09.2021 |
SB2021092806 |
||
| #VU56157 - Missing release of memory after effective lifetime CVE-2021-23047 |
CWE-401 | Medium | 14.1.4.3, 15.1.3.1, 16.1.0 | 30.08.2021 |
SB2021083010 |
||
| #VU56088 - Improper input validation CVE-2021-23045 |
CWE-20 | Low | 13.1.4.1, 14.1.4.3, 15.1.3.1, 16.0.1.2, 16.1.0 | 25.08.2021 |
SB2021082512 |
||
| #VU56064 - Out-of-bounds read CVE-2021-3712 |
CWE-125 | Medium | - | 24.08.2021 |
SB2021082414 SB2021082508 SB2021082510 and 142 more |
||
| #VU52751 - Improper Access Control CVE-2021-23016 |
CWE-284 | Medium | 13.1.4, 14.1.4.1, 15.1.3 | 29.04.2021 |
SB2021042919 |
||
| #VU52749 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2021-23009 |
CWE-835 | Medium | 15.1.3, 16.0.1.1 | 29.04.2021 |
SB2021042917 |
||
| #VU52738 - Improper Authentication CVE-2021-23008 |
CWE-287 | High | 12.1.6, 13.1.4, 14.1.4, 15.1.3 | 29.04.2021 |
SB2021042905 |
||
| #VU51494 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2021-22988 |
CWE-78 | High | 11.6.5.3, 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1 | 16.03.2021 |
SB2021031607 |
||
| #VU51493 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2021-22987 |
CWE-78 | High | 11.6.5.3, 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1 | 16.03.2021 |
SB2021031606 |
||
| #VU51491 - Resource Management Errors CVE-2021-23003 |
CWE-399 | Medium | 11.6.5.3, 12.1.5.3, 13.1.3.6, 14.1.3.1, 15.1.2, 16.0.1.1 | 16.03.2021 |
SB2021031604 |
Showing elements 1 - 20 out of 86