VendorsF5big-ip_application_security_managerall versions
Vulnerabilities

F5 Big-ip Application Security Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

580CVEs
CVE-2026-41225
iControl REST vulnerability
Published 2026-05-13 · Analyzed
9.1EPSS 0.005
CVE-2022-34865
Traffic intelligence feeds vulnerability CVE-2022-34865
Published 2022-08-04 · Modified
9.1EPSS 0.004
CVE-2015-3628
The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6, BIG-IP AAM 11.4.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6, BIG-IP Edge Gateway, WebAccelerator, and WOM 11.3.0, BIG-IP GTM 11.3.0 before 11.6.0 HF6, BIG-IP PSM 11.3.0 through 11.4.1, Enterprise Manager 3.1.0 through 3.1.1, BIG-IQ Cloud and Security 4.0.0 through 4.5.0, BIG-IQ Device 4.2.0 through 4.5.0, and BIG-IQ ADC 4.5.0 allows remote authenticated users with the "Resource Administrator" role to gain privileges via an iCall (1) script or (2) handler in a SOAP request to iControl/iControlPortal.cgi.
Published 2015-12-07 · Modified
9.01 PoCEPSS 0.693
CVE-2021-22988
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, TMUI, also referred to as the Configuration utility, has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Published 2021-03-31 · Modified
9.0EPSS 0.104
CVE-2021-22990
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, on systems with Advanced WAF or BIG-IP ASM provisioned, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Published 2021-03-31 · Modified
9.0EPSS 0.088
CVE-2012-3163
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Information Schema.
Published 2012-10-17 · Modified
9.0EPSS 0.051
CVE-2015-7394
The datastor kernel module in F5 BIG-IP Analytics, APM, ASM, Link Controller, and LTM 11.1.0 before 12.0.0, BIG-IP AAM 11.4.0 before 12.0.0, BIG-IP AFM, PEM 11.3.0 before 12.0.0, BIG-IP Edge Gateway, WebAccelerator, and WOM 11.1.0 through 11.3.0, BIG-IP GTM 11.1.0 through 11.6.0, BIG-IP PSM 11.1.0 through 11.4.1, BIG-IQ Cloud and Security 4.0.0 through 4.5.0, BIG-IQ Device 4.2.0 through 4.5.0, BIG-IQ ADC 4.5.0, and Enterprise Manager 3.0.0 through 3.1.1 allows remote authenticated users to cause a denial of service or gain privileges by leveraging permission to upload and execute code.
Published 2015-11-06 · Modified
9.0EPSS 0.039
CVE-2016-5020
F5 BIG-IP before 12.0.0 HF3 allows remote authenticated users to modify the account configuration of users with the Resource Administration role and gain privilege via a crafted external Extended Application Verification (EAV) monitor script.
Published 2016-06-30 · Modified
9.0EPSS 0.034
CVE-2019-6642
In BIG-IP 15.0.0, 14.0.0-14.1.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.2, and 11.5.2-11.6.4, BIG-IQ 6.0.0-6.1.0 and 5.1.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, authenticated users with the ability to upload files (via scp, for example) can escalate their privileges to allow root shell access from within the TMOS Shell (tmsh) interface. The tmsh interface allows users to execute a secondary program via tools like sftp or scp.
Published 2019-07-01 · Modified
9.0EPSS 0.018
CVE-2021-23038
On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2021-09-14 · Modified
9.0EPSS 0.009
CVE-2025-20058
BIG-IP message routing vulnerability
Published 2025-02-05 · Analyzed
8.9EPSS 0.004
CVE-2025-24326
BIG-IP Advanced WAF/ASM BADoS vulnerability
Published 2025-02-05 · Analyzed
8.9EPSS 0.004
CVE-2025-21087
TMM Vulnerability
Published 2025-02-05 · Analyzed
8.9EPSS 0.004
CVE-2022-41622
iControl SOAP vulnerability
Published 2022-12-07 · Modified
8.8EPSS 0.923
CVE-2025-20029
BIG-IP iControl REST and tmsh vulnerability
Published 2025-02-05 · Analyzed
8.8EPSS 0.072
CVE-2023-46748
BIG-IP Configuration utility authenticated SQL injection vulnerability
Published 2023-10-26 · Analyzed
8.8KEVEPSS 0.045
CVE-2021-23025
On version 15.1.x before 15.1.0.5, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all versions of 12.1.x and 11.6.x, an authenticated remote command execution vulnerability exists in the BIG-IP Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2021-09-14 · Modified
8.8EPSS 0.023
CVE-2016-9251
In F5 BIG-IP 12.0.0 through 12.1.2, an authenticated attacker may be able to cause an escalation of privileges through a crafted iControl REST connection.
Published 2017-05-09 · Modified
8.8EPSS 0.015
CVE-2019-6646
On BIG-IP 11.5.2-11.6.4 and Enterprise Manager 3.1.1, REST users with guest privileges may be able to escalate their privileges and run commands with admin privileges.
Published 2019-09-04 · Modified
8.8EPSS 0.015
CVE-2021-22993
On BIG-IP Advanced WAF and BIG-IP ASM versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, DOM-based XSS on DoS Profile properties page. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Published 2021-03-31 · Modified
8.8EPSS 0.009
CVE-2021-23029
On version 16.0.x before 16.0.1.2, insufficient permission checks may allow authenticated users with guest privileges to perform Server-Side Request Forgery (SSRF) attacks through F5 Advanced Web Application Firewall (WAF) and the BIG-IP ASM Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2021-09-14 · Modified
8.8EPSS 0.009
CVE-2026-41957
BIG-IP and BIG-IQ Configuration utility vulnerability
Published 2026-05-13 · Analyzed
8.8EPSS 0.009
CVE-2021-23014
On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, and 14.1.x before 14.1.4, BIG-IP Advanced WAF and ASM are missing authorization checks for file uploads to a specific directory within the REST API which might allow Authenticated users with guest privileges to upload files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2021-05-10 · Modified
8.8EPSS 0.008
CVE-2020-5904
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a cross-site request forgery (CSRF) vulnerability in the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, exists in an undisclosed page.
Published 2020-07-01 · Modified
8.8EPSS 0.006
CVE-2021-23026
BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x and all versions of BIG-IQ 8.x, 7.x, and 6.x are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2021-09-14 · Modified
8.8EPSS 0.005
CVE-2022-41800
Appliance mode iControl REST vulnerability
Published 2022-12-07 · Modified
8.7EPSS 0.769
CVE-2025-31644
Appliance mode BIG-IP iControl REST and tmsh vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.265
CVE-2022-27806
On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP Advanced WAF, ASM, and ASM, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, when running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing command injection vulnerabilities in undisclosed URIs in F5 BIG-IP Guided Configuration. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Published 2022-05-05 · Modified
8.7EPSS 0.015
CVE-2026-34176
Knowledge Appliance mode iControl REST vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.009
CVE-2024-22093
Appliance mode iControl REST vulnerability
Published 2024-02-14 · Analyzed
8.7EPSS 0.008
CVE-2025-23239
BIG-IP iControl REST vulnerability
Published 2025-02-05 · Analyzed
8.7EPSS 0.008
CVE-2026-42930
Appliance mode iControl REST vulnerability
Published 2026-05-13 · Undergoing Analysis
8.7EPSS 0.006
CVE-2026-39455
BIG-IP Configuration utility vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.005
CVE-2024-39778
BIG-IP HSB vulnerability
Published 2024-08-14 · Analyzed
8.7EPSS 0.005
CVE-2024-41727
BIG-IP TMM vulnerability
Published 2024-08-14 · Analyzed
8.7EPSS 0.005
CVE-2026-41227
BIG-IP HTTP/2 Layer 7 Dos Protection vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.005
CVE-2026-41218
BIG-IP PEM iRules vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.005
CVE-2026-42409
BIG-IP HTTP/2 vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.005
CVE-2026-40618
BIG-IP SSL/TLS vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.005
CVE-2026-40423
BIG-IP SIP profile vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.005
← Prev2 / 15Next →