An SQL injection vulnerability exists in an undisclosed page of the BIG-IP Configuration utility.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
References
Link | Resource |
---|---|
https://my.f5.com/manage/s/article/K000138047 | Vendor Advisory |
https://my.f5.com/manage/s/article/K000138047 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
23 Jan 2025, 19:52
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:f5:big-ip_application_security_manager:17.1.0:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:17.1.0:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* |
|
First Time |
F5 big-ip Advanced Web Application Firewall
F5 big-ip Application Security Manager F5 |
|
References | () https://my.f5.com/manage/s/article/K000138047 - Vendor Advisory |
21 Nov 2024, 08:57
Type | Values Removed | Values Added |
---|---|---|
References | () https://my.f5.com/manage/s/article/K000138047 - | |
Summary |
|
14 Feb 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-14 17:15
Updated : 2025-01-23 19:52
NVD link : CVE-2024-23603
Mitre link : CVE-2024-23603
CVE.ORG link : CVE-2024-23603
JSON object : View
Products Affected
f5
- big-ip_application_security_manager
- big-ip_advanced_web_application_firewall
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')