Security restrictions bypass in F5 Networks products - CVE-2018-15316
Published: October 22, 2018 / Updated: October 23, 2018
Vulnerability details
The vulnerability allows a local attacker to bypass security restrictions on the target system.
The vulnerability exists due to the software loads the policy library with user permission and bypassing the endpoint checks. A local attacker can bypass the endpoint checks and modify data on the target system.
Affected software
BIG-IP APM
BIG-IP Edge Client for Linux
How to mitigate CVE-2018-15316
Update BIG-IP APM Clients to version 7.1.7.
Update BIG-IP Edge Client to version 7170.
BIG-IP APM - update to 13.1.1.2
BIG-IP Edge Client for Linux - update to 7170