Tracker / CVE-2015-7394
CVE-2015-7394
High 9.0
The datastor kernel module in F5 BIG-IP Analytics, APM, ASM, Link Controller, and LTM 11.1.0 before 12.0.0, BIG-IP AAM 11.4.0 before 12.0.0, BIG-IP AFM, PEM 11.3.0 before 12.0.0, BIG-IP Edge Gateway, WebAccelerator, and WOM 11.1.0 through 11.3.0, BIG-IP GTM 11.1.0 through 11.6.0, BIG-IP PSM 11.1.0 through 11.4.1, BIG-IQ Cloud and Security 4.0.0 through 4.5.0, BIG-IQ Device 4.2.0 through 4.5.0, BIG-IQ ADC 4.5.0, and Enterprise Manager 3.0.0 through 3.1.1 allows remote authenticated users to cause a denial of service or gain privileges by leveraging permission to upload and execute code.
Affected products and versions
| f5 | big-ip_access_policy_manager |
|---|---|
| f5 | big-ip_advanced_firewall_manager |
| f5 | big-ip_analytics |
| f5 | big-ip_application_acceleration_manager |
| f5 | big-ip_application_security_manager |
| f5 | big-ip_edge_gateway |
| f5 | big-ip_enterprise_manager |
| f5 | big-ip_global_traffic_manager |
| f5 | big-ip_link_controller |
| f5 | big-ip_local_traffic_manager |
| f5 | big-ip_policy_enforcement_manager |
| f5 | big-ip_protocol_security_module |
| f5 | big-ip_wan_optimization_manager |
| f5 | big-ip_webaccelerator |
| f5 | big-iq_adc |
| f5 | big-iq_cloud |
| f5 | big-iq_device |
| f5 | big-iq_security |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.