Known vulnerabilities in BIG-IP APM - page 6
Vendor:
F5 Networks
Software:
BIG-IP APM
Software CPE:
cpe:2.3:h:f5_networks:big-ip_apm:*:*:*:*:*:*:*:*
Website:
https://f5.com/
Total vulnerabilities:
193
Public exploits:
15
Known exploited (KEV):
4
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
12.1.3.3
13.1.3.3
13.1.1.4
13.1.1.3
13.1.1.1
13.1.0.7
13.1.0.5
13.1.0.4
14.1.2.2
15.1.10.8
17.5.1
17.5.0
17.1.3.1
17.5.1.3
17.1.3
16.1.6.1
16.1.6
17.1.2.2
17.1.2.1
15.1.10.6.0.11.6
17.1.2
17.1.0.3
17.1.0.2
17.1.0.1
16.1.5
16.1.4.3
16.1.4.1
16.1.4
16.1.3.5
16.1.3.4
16.1.2.1
15.1.10
15.1.9.1
15.1.9
15.1.8.2
15.1.8.1
15.1.8
15.1.0.3
15.1.10.3
16.1.4.2
17.1.1
17.1.03
15.1.0
17.1.0
14.1.5.2
16.1.3.2
17.0.0.1
15.1.7
16.1.3.3
17.0.0.2
14.1.5.3
14.1.5
15.1.6
16.1.3
14.1.5.1
15.1.6.1
16.1.3.1
17.0.0
13.1.5
14.1.4.6
15.1.5.1
16.1.2.2
15.1.5
14.1.4.5
16.1.1
15.1.4.1
16.1.2
15.1.4
14.1.4.4
16.1.0
13.1.4.1
14.1.4.3
15.1.3.1
16.0.1.2
14.1.4.1
12.1.6
13.1.4
15.1.3
13.1.3.6 2
14.1.4 2
15.1.2.1 2
16.0.1.1 2
11.6.5.3
12.1.5.3
14.1.4
13.1.3.6
15.1.2.1
16.0.1.1
13.1.3.1
14.1.3.1
14.1.2.8
13.1.3.5
14.1.3
16.0.1
15.1.2
15.1.1
13.0.0 HF3
12.1.2 HF2
11.6.2 HF1
14.1.2.7
15.1.0.5
16.0.0
14.1.2-0.89.37
14.1.2.5
15.0.1.4
15.1.0.4
14.1.2.6
13.1.3.4
12.1.5.2
11.6.5.2
14.1.2.4
15.0.1.3
15.0.1.2
15.1.0.2
15.1.0.1
14.1.2.3
12.1.5.1
13.1.3.2
15.0.1.1
14.1.0.6
14.0.0.5
11.6.5.1
11.5.7
11.5.8
11.5.9
11.5.10
11.6.5
12.1.4
12.1.5
15.0.1
15.1.0
15.0.0
14.1.2.1.0.122.4-ENG Hotfix
14.1.2.1.0.115.4-ENG Hotfix
14.1.2.1.0.111.4-ENG Hotfix
14.1.2.1.0.105.4-ENG Hotfix
14.1.2.1.0.99.4-ENG Hotfix
14.1.2.1.0.97.4-ENG Hotfix
14.1.2.1.0.34.4-ENG Hotfix
14.1.2.1.0.16.4-ENG Hotfix
14.1.2.1.0.14.4-ENG Hotfix
14.1.2.1.0.46.4-ENG Hotfix
14.1.2.0.32.37-ENG Hotfix
14.1.2.0.18.37-ENG Hotfix
14.1.2.0.11.37-ENG Hotfix
14.1.0.6.0.70.9-ENG Hotfix
14.1.0.6.0.68.9-ENG Hotfix
14.1.0.6.0.14.9-ENG Hotfix
14.1.0.6.0.11.9-ENG Hotfix
14.1.0.5.0.40.5-ENG Hotfix
14.1.0.5.0.36.5-ENG Hotfix
14.1.0.5.0.15.5-ENG Hotfix
14.1.0.3.0.99.6-ENG Hotfix
14.1.0.3.0.97.6-ENG Hotfix
14.1.0.3.0.79.6-ENG Hotfix
15.0.1.0.48.11-ENG Hotfix
15.0.1.0.33.11-ENG Hotfix
13.1.1.5
14.1.2
14.1.1
14.0.1.1
14.1.2.1
13.1.3
11.6.4
14.1.0
14.0.1
14.0.0
13.1.1.2
7.1.6.1
7.1.7.1
7.1.7
7.1.6
13.1.1
13.1.0.8
12.1.3.2
12.1.3.4
13.1.0.6
11.6.3
12.1.3.1
13.0.1
11.5.6
11.5.5
11.5.4 HF4
12.1.3
13.1.0.3
13.1.0.2
13.1.0.1
13.1.0
11.5.3
11.5.2
11.5.1
11.5.0
11.6.2
11.4.0
11.2.1
11.5.4
11.5.1 HF6
11.6.0
12.0.1
12.1.2 HF1
13.0.0
12.1.0 HF1
12.0 HF4
12.0 HF3
12.0 HF1
12.1.2
12.0.0
11.6.1 HF1
12.1.1
12.1.0
11.6.1
Vulnerabilities (193)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU27876 - Access of Uninitialized Pointer CVE-2020-5898 |
CWE-824 | Low | - | 13.05.2020 |
SB2020051317 |
||
| #VU27561 - Improper input validation CVE-2020-5872 |
CWE-20 | Medium | 12.1.5, 13.1.3.2, 14.0.1.1, 14.1.2.4, 15.0.0 | 06.05.2020 |
SB2020050613 |
||
| #VU27528 - Improper input validation CVE-2020-5875 |
CWE-20 | Medium | 14.1.2.4, 15.0.1.1, 15.1.0 | 05.05.2020 |
SB2020050510 |
||
| #VU27520 - Missing Encryption of Sensitive Data CVE-2020-5886 |
CWE-311 | Medium | 14.1.2.4, 15.1.0.2 | 05.05.2020 |
SB2020050509 |
||
| #VU27518 - Security Features CVE-2020-5884 |
CWE-254 | Medium | 16.0.0 | 05.05.2020 |
SB2020050507 |
||
| #VU27517 - Improper Authentication CVE-2020-5888 |
CWE-287 | Medium | 14.1.2.4, 15.0.1.3, 15.1.0.2 | 05.05.2020 |
SB2020050509 |
||
| #VU49042 - Missing release of memory after effective lifetime CVE-2020-5883 |
CWE-401 | Medium | 13.1.3.2, 14.0.1.1, 14.1.2.4, 15.0.1.1 | 30.04.2020 |
SB2020043038 |
||
| #VU27467 - Unrestricted Upload of File with Dangerous Type CVE-2020-5880 |
CWE-434 | Medium | 14.1.2.4, 15.1.0 | 30.04.2020 |
SB2020043025 |
||
| #VU27466 - Exposure of sensitive information to an unauthorized actor |
CWE-200 | Medium | 14.1.2.4, 15.0.1.3, 15.1.0 | 30.04.2020 |
SB2020043025 |
||
| #VU27465 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2020-5889 |
CWE-79 | Low | 14.1.2.4, 15.0.1.3, 15.1.0.2 | 30.04.2020 |
SB2020043025 |
||
| #VU27464 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2020-5893 |
CWE-300 | Low | - | 30.04.2020 |
SB2020043023 |
||
| #VU27463 - Improper input validation CVE-2020-5874 |
CWE-20 | Medium | 14.0.1.1, 14.1.2.4, 15.0.1.3, 15.1.0 | 30.04.2020 |
SB2020043024 |
||
| #VU26465 - Improper input validation CVE-2020-5857 |
CWE-20 | Medium | 12.1.5.1, 13.1.3.2, 14.1.2.3, 15.0.1.1, 15.1.0 | 30.03.2020 |
SB2020033010 |
||
| #VU26463 - Command injection CVE-2020-5858 |
CWE-77 | Low | 12.1.5.1, 14.1.2.3, 15.1.0 | 30.03.2020 |
SB2020033010 |
||
| #VU26461 - Improper input validation CVE-2020-5862 |
CWE-20 | Low | 14.1.2.3, 15.0.1.2, 15.1.0.2 | 30.03.2020 |
SB2020033009 |
||
| #VU26460 - Improper input validation CVE-2020-5859 |
CWE-20 | Medium | 15.1.0.2 | 30.03.2020 |
SB2020033010 |
||
| #VU26459 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2020-5860 |
CWE-300 | Medium | - | 30.03.2020 |
SB2020033008 |
||
| #VU26456 - Missing release of memory after effective lifetime CVE-2020-5861 |
CWE-401 | Low | 12.1.5.1 | 30.03.2020 |
SB2020033010 |
||
| #VU25004 - Improper input validation CVE-2020-5856 |
CWE-20 | Low | 14.1.2.3, 15.1.0 | 06.02.2020 |
SB2020020605 |
||
| #VU25003 - Improper Authentication CVE-2020-5855 |
CWE-287 | Low | - | 06.02.2020 |
SB2020020604 |
Showing elements 101 - 120 out of 193