VendorsF5big-ip_access_policy_managerany version
Vulnerabilities

F5 Big-ip Access Policy Manager any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

516CVEs
CVE-2019-6597
In BIG-IP 13.0.0-13.1.1.1, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8 or Enterprise Manager 3.1.1, when authenticated administrative users run commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.
Published 2019-03-13 · Modified
7.2EPSS 0.013
CVE-2018-15327
In BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1 or Enterprise Manager 3.1.1, when authenticated administrative users run commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.
Published 2018-10-31 · Modified
7.2EPSS 0.012
CVE-2018-15329
On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.7, or Enterprise Manager 3.1.1, when authenticated administrative users run commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.
Published 2018-12-20 · Modified
7.2EPSS 0.012
CVE-2022-35735
BIG-IP monitor configuration vulnerability CVE-2022-35735
Published 2022-08-04 · Modified
7.2EPSS 0.009
CVE-2023-42768
BIG-IP iControl REST vulnerability
Published 2023-10-10 · Modified
7.2EPSS 0.005
CVE-2024-22389
BIG-IP iControl REST API Vulnerability
Published 2024-02-14 · Analyzed
7.2EPSS 0.005
CVE-2020-5880
Om BIG-IP 15.0.0-15.0.1.3 and 14.1.0-14.1.2.3, the restjavad process may expose a way for attackers to upload arbitrary files on the BIG-IP system, bypassing the authorization system. Resulting error messages may also reveal internal paths of the server.
Published 2020-04-30 · Modified
7.1EPSS 0.013
CVE-2019-6608
On BIG-IP 11.5.1-11.6.3, 12.1.0-12.1.3, 13.0.0-13.1.1.1, and 14.0.0-14.0.0.2, under certain conditions, the snmpd daemon may leak memory on a multi-blade BIG-IP vCMP guest when processing authorized SNMP requests.
Published 2019-03-28 · Modified
7.1EPSS 0.010
CVE-2026-42919
F5 BIG-IP Appliance Mode Vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.004
CVE-2025-47148
BIG-IP APM and SSL Orchestrator vulnerability
Published 2025-10-15 · Analyzed
7.1EPSS 0.004
CVE-2026-41219
BIG-IP QKView vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.004
CVE-2026-40699
BIG-IP Configuration utility vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.004
CVE-2026-40462
iControl REST and tmsh vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.003
CVE-2026-35062
iControl SOAP vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.003
CVE-2020-5912
In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the restjavad process's dump command does not follow current best coding practices and may overwrite arbitrary files.
Published 2020-08-26 · Modified
7.1EPSS 0.003
CVE-2026-42937
iControl REST and tmsh vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.003
CVE-2026-41959
iControl and tmsh REST vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.003
CVE-2026-42781
BIG-IP FastL4 virtual server vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.003
CVE-2023-43124
BIG-IP APM Clients TunnelCrack vulnerability
Published 2023-09-27 · Modified
7.1EPSS 0.002
CVE-2023-36858
BIG-IP Edge Client for Windows and macOS vulnerability
Published 2023-08-02 · Modified
7.1EPSS 0.001
CVE-2018-15332
The svpn component of the F5 BIG-IP APM client prior to version 7.1.7.2 for Linux and macOS runs as a privileged process and can allow an unprivileged user to get ownership of files owned by root on the local client host in a race condition.
Published 2018-12-06 · Modified
7.0EPSS 0.003
CVE-2014-0196
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.
Published 2014-05-07 · Analyzed
6.9KEV1 PoCEPSS 0.225
CVE-2025-54755
BIG-IP Configuration utility vulnerability
Published 2025-10-15 · Analyzed
6.9EPSS 0.012
CVE-2026-24464
Appliance mode iControl REST vulnerability
Published 2026-05-13 · Analyzed
6.9EPSS 0.009
CVE-2025-54500
HTTP/2 Vulnerability
Published 2025-08-13 · Analyzed
6.9EPSS 0.005
CVE-2025-59268
BIG-IP Configuration utility vulnerability
Published 2025-10-15 · Analyzed
6.9EPSS 0.004
CVE-2026-41954
iControl REST and tmsh vulnerability
Published 2026-05-13 · Analyzed
6.9EPSS 0.004
CVE-2026-42063
iControl SOAP vulnerability
Published 2026-05-13 · Analyzed
6.9EPSS 0.004
CVE-2026-40435
BIG-IP httpd access control vulnerability
Published 2026-05-13 · Analyzed
6.9EPSS 0.003
CVE-2019-6604
On BIG-IP 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3.6, 13.0.0-13.1.1.1, and 14.0.0-14.0.0.2, under certain conditions, hardware systems with a High-Speed Bridge and using non-default Layer 2 forwarding configurations may experience a lockup of the High-Speed Bridge.
Published 2019-03-28 · Modified
6.8EPSS 0.010
CVE-2022-23014
On versions 16.1.x before 16.1.2 and 15.1.x before 15.1.4.1, when BIG-IP APM portal access is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2022-01-25 · Modified
6.8EPSS 0.008
CVE-2020-5916
In BIG-IP versions 15.1.0-15.1.0.4 and 15.0.0-15.0.1.3 the Certificate Administrator user role and higher privileged roles can perform arbitrary file reads outside of the web root directory.
Published 2020-08-26 · Modified
6.8EPSS 0.005
CVE-2020-5892
In versions 7.1.5-7.1.8, the BIG-IP Edge Client components in BIG-IP APM, Edge Gateway, and FirePass legacy allow attackers to obtain the full session ID from process memory.
Published 2020-04-30 · Modified
6.7EPSS 0.003
CVE-2022-33962
BIG-IP iRule vulnerability CVE-2022-33962
Published 2022-08-04 · Modified
6.7EPSS 0.002
CVE-2024-21782
BIG-IP and BIG-IQ secure copy vulnerability
Published 2024-02-14 · Analyzed
6.7EPSS 0.002
CVE-2026-42408
BIG-IP DNS tmsh vulnerability
Published 2026-05-13 · Analyzed
6.7EPSS 0.001
CVE-2019-6617
On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, a user with the Resource Administrator role is able to overwrite sensitive low-level files (such as /etc/passwd) using SFTP to modify user permissions, without Advanced Shell access. This is contrary to our definition for the Resource Administrator (RA) role restrictions.
Published 2019-05-03 · Modified
6.5EPSS 0.022
CVE-2019-6641
On BIG-IP 12.1.0-12.1.4.1, undisclosed requests can cause iControl REST processes to crash. The attack can only come from an authenticated user; all roles are capable of performing the attack. Unauthenticated users cannot perform this attack.
Published 2019-07-03 · Modified
6.5EPSS 0.020
CVE-2021-23043
On BIG-IP, on all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to access arbitrary files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2021-09-14 · Modified
6.5EPSS 0.020
CVE-2019-6638
On BIG-IP 14.1.0-14.1.0.5 and 14.0.0-14.0.0.4, Malformed http requests made to an undisclosed iControl REST endpoint can lead to infinite loop of the restjavad process.
Published 2019-07-03 · Modified
6.5EPSS 0.020
← Prev9 / 13Next →