imPC@ndo EN

Tracker / CVE-2019-6642

CVE-2019-6642

Alta 8.8

In BIG-IP 15.0.0, 14.0.0-14.1.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.2, and 11.5.2-11.6.4, BIG-IQ 6.0.0-6.1.0 and 5.1.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, authenticated users with the ability to upload files (via scp, for example) can escalate their privileges to allow root shell access from within the TMOS Shell (tmsh) interface. The tmsh interface allows users to execute a secondary program via tools like sftp or scp.

Prodotti e versioni affette

f5 big-ip_access_policy_manager
f5 big-ip_access_policy_manager · 11.5.2 → 11.6.4
f5 big-ip_access_policy_manager · 12.1.0 → 12.1.4.2
f5 big-ip_access_policy_manager · 13.0.0 → 13.1.1.5
f5 big-ip_access_policy_manager · 14.0.0 → 14.1.0.5
f5 big-ip_advanced_firewall_manager
f5 big-ip_advanced_firewall_manager · 11.5.2 → 11.6.4
f5 big-ip_advanced_firewall_manager · 12.1.0 → 12.1.4.2
f5 big-ip_advanced_firewall_manager · 13.0.0 → 13.1.1.5
f5 big-ip_advanced_firewall_manager · 14.0.0 → 14.1.0.5
f5 big-ip_analytics
f5 big-ip_analytics · 11.5.2 → 11.6.4
f5 big-ip_analytics · 12.1.0 → 12.1.4.2
f5 big-ip_analytics · 13.0.0 → 13.1.1.5
f5 big-ip_analytics · 14.0.0 → 14.1.0.5
f5 big-ip_application_acceleration_manager
f5 big-ip_application_acceleration_manager · 11.5.2 → 11.6.4
f5 big-ip_application_acceleration_manager · 12.1.0 → 12.1.4.2
f5 big-ip_application_acceleration_manager · 13.0.0 → 13.1.1.5
f5 big-ip_application_acceleration_manager · 14.0.0 → 14.1.0.5
f5 big-ip_application_security_manager
f5 big-ip_application_security_manager · 11.5.2 → 11.6.4
f5 big-ip_application_security_manager · 12.1.0 → 12.1.4.2
f5 big-ip_application_security_manager · 13.0.0 → 13.1.1.5
f5 big-ip_application_security_manager · 14.0.0 → 14.1.0.5
f5 big-ip_domain_name_system
f5 big-ip_domain_name_system · 11.5.2 → 11.6.4
f5 big-ip_domain_name_system · 12.1.0 → 12.1.4.2
f5 big-ip_domain_name_system · 13.0.0 → 13.1.1.5
f5 big-ip_domain_name_system · 14.0.0 → 14.1.0.5
f5 big-ip_edge_gateway
f5 big-ip_edge_gateway · 11.5.2 → 11.6.4
f5 big-ip_edge_gateway · 12.1.0 → 12.1.4.2
f5 big-ip_edge_gateway · 13.0.0 → 13.1.1.5
f5 big-ip_edge_gateway · 14.0.0 → 14.1.0.5
f5 big-ip_fraud_protection_service
f5 big-ip_fraud_protection_service · 11.5.2 → 11.6.4
f5 big-ip_fraud_protection_service · 12.1.0 → 12.1.4.2
f5 big-ip_fraud_protection_service · 13.0.0 → 13.1.1.5
f5 big-ip_fraud_protection_service · 14.0.0 → 14.1.0.5
f5 big-ip_global_traffic_manager
f5 big-ip_global_traffic_manager · 11.5.2 → 11.6.4
f5 big-ip_global_traffic_manager · 12.1.0 → 12.1.4.2
f5 big-ip_global_traffic_manager · 13.0.0 → 13.1.1.5
f5 big-ip_global_traffic_manager · 14.0.0 → 14.1.0.5
f5 big-ip_link_controller
f5 big-ip_link_controller · 11.5.2 → 11.6.4
f5 big-ip_link_controller · 12.1.0 → 12.1.4.2
f5 big-ip_link_controller · 13.0.0 → 13.1.1.5
f5 big-ip_link_controller · 14.0.0 → 14.1.0.5
f5 big-ip_local_traffic_manager
f5 big-ip_local_traffic_manager · 11.5.2 → 11.6.4
f5 big-ip_local_traffic_manager · 12.1.0 → 12.1.4.2
f5 big-ip_local_traffic_manager · 13.0.0 → 13.1.1.5
f5 big-ip_local_traffic_manager · 14.0.0 → 14.1.0.5
f5 big-ip_policy_enforcement_manager
f5 big-ip_policy_enforcement_manager · 11.5.2 → 11.6.4
f5 big-ip_policy_enforcement_manager · 12.1.0 → 12.1.4.2
f5 big-ip_policy_enforcement_manager · 13.0.0 → 13.1.1.5
f5 big-ip_policy_enforcement_manager · 14.0.0 → 14.1.0.5

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti