imPC@ndo IT

Tracker / CVE-2019-6658

CVE-2019-6658

Medium 4.3

On BIG-IP AFM 15.0.0-15.0.1, 14.0.0-14.1.2, 13.1.0-13.1.3.1, and 12.1.0-12.1.5, a vulnerability in the AFM configuration utility may allow any authenticated BIG-IP user to run an SQL injection attack.

Affected products and versions

f5 big-ip_advanced_firewall_manager · 12.1.0 → 12.1.5
f5 big-ip_advanced_firewall_manager · 13.1.0 → 13.1.3
f5 big-ip_advanced_firewall_manager · 14.0.0 → 14.1.2.1
f5 big-ip_advanced_firewall_manager · 15.0.0 → 15.0.1

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References