CVE-2015-4040

Directory traversal vulnerability in the configuration utility in F5 BIG-IP before 12.0.0 and Enterprise Manager 3.0.0 through 3.1.1 allows remote authenticated users to access arbitrary files in the web root via unspecified vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:f5:enterprise_manager:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:enterprise_manager:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:enterprise_manager:3.1.1:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_protocol_security_module:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_wan_optimization_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:30

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/133931/F5-BigIP-10.2.4-Build-595.0-HF3-Path-Traversal.html - () http://packetstormsecurity.com/files/133931/F5-BigIP-10.2.4-Build-595.0-HF3-Path-Traversal.html -
References () http://www.securitytracker.com/id/1033532 - () http://www.securitytracker.com/id/1033532 -
References () http://www.securitytracker.com/id/1033533 - () http://www.securitytracker.com/id/1033533 -
References () https://support.f5.com/kb/en-us/solutions/public/17000/200/sol17253.html - Vendor Advisory () https://support.f5.com/kb/en-us/solutions/public/17000/200/sol17253.html - Vendor Advisory

Information

Published : 2015-09-17 16:59

Updated : 2024-11-21 02:30


NVD link : CVE-2015-4040

Mitre link : CVE-2015-4040

CVE.ORG link : CVE-2015-4040


JSON object : View

Products Affected

f5

  • big-ip_application_security_manager
  • big-ip_protocol_security_module
  • big-ip_application_acceleration_manager
  • big-ip_global_traffic_manager
  • big-ip_policy_enforcement_manager
  • big-ip_edge_gateway
  • big-ip_wan_optimization_manager
  • big-ip_link_controller
  • big-ip_local_traffic_manager
  • big-ip_webaccelerator
  • big-ip_advanced_firewall_manager
  • big-ip_access_policy_manager
  • enterprise_manager
  • big-ip_analytics
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')