#VU62824 Path traversal in BIG-IP - CVE-2022-26835
Published: May 5, 2022
BIG-IP
F5 Networks
Description
The vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists due to input validation error in iControl REST and tmsh command when processing directory traversal sequences in BIG-IP systems deployed in Standard and Appliance mode. An attacker with at least resource administrator role privileges can send a specially crafted HTTP request to the iControl REST API or pass specially crafted arguments to the tmsh command and view contents of arbitrary files on the system.