Resource exhaustion in F5 SSL Orchestrator and BIG-IP APM - CVE-2022-33203
Published: August 4, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to system does not properly control consumption of internal resources when a BIG-IP APM access policy with Service Connect agent is configured on a virtual server. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
BIG-IP APM
How to mitigate CVE-2022-33203
BIG-IP APM - addressed in versions 14.1.5, 15.1.6.1, 16.1.3