#VU66145 Deserialization of Untrusted Data in BIG-IP DNS - CVE-2022-33947
Published: August 5, 2022
BIG-IP DNS
F5 Networks
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to insecure input validation when processing serialized data in the Traffic Management User Interface (TMUI). A remote user can cause the Tomcat process to restart and perform unauthorized DNS requests and operations through undisclosed requests.