Lucene search

K
cve[email protected]CVE-2014-8727
HistoryNov 17, 2014 - 4:59 p.m.

CVE-2014-8727

2014-11-1716:59:07
CWE-22
web.nvd.nist.gov
35
f5 big-ip
cve-2014-8727
directory traversal
vulnerability
nvd
tmui
control
jspmap
system
archive
properties
jsp
form

6.2 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:S/C:N/I:C/A:C

6.5 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

27.0%

Multiple directory traversal vulnerabilities in F5 BIG-IP before 10.2.2 allow local users with the “Resource Administrator” or “Administrator” role to enumerate and delete arbitrary files via a … (dot dot) in the name parameter to (1) tmui/Control/jspmap/tmui/system/archive/properties.jsp or (2) tmui/Control/form.

Affected configurations

NVD
Node
f5big-ip_local_traffic_managerRange10.2.1

6.2 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:S/C:N/I:C/A:C

6.5 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

27.0%