vendor:
BIG-IP
by:
Karn Ganeshen
8,8
CVSS
HIGH
File Path Traversal
22
CWE
Product Name: BIG-IP
Affected Version From: F5 BIG-IP 10.2.4 Build 595.0 Hotfix HF3
Affected Version To: Multiple Additional F5 products & versions
Patch Exists: YES
Related CWE: CVE-2015-4040
CPE: a:f5:big-ip
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
F5 BigIP File Path Traversal Vulnerability
The handler parameter is vulnerable to file path manipulation attacks. When we submit a payload */tmui/locallb/virtual_server/../../../../WEB-INF/web.xml* in the *handler* parameter, the file *WEB-INF/web.xml* is returned.
Mitigation:
F5 has released a patch for this vulnerability. It is recommended to update to the latest version of F5 BIG-IP.