Lucene search

K
cvelistF5CVELIST:CVE-2021-23040
HistorySep 14, 2021 - 2:42 p.m.

CVE-2021-23040

2021-09-1414:42:51
CWE-89
f5
www.cve.org
4
sql injection
big-ip afm
security vulnerability

EPSS

0.001

Percentile

37.0%

On BIG-IP AFM version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a SQL injection vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. This issue is exposed only when BIG-IP AFM is provisioned. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CNA Affected

[
  {
    "product": "BIG-IP AFM",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x"
      }
    ]
  }
]

EPSS

0.001

Percentile

37.0%

Related for CVELIST:CVE-2021-23040