vendor:
BIG-IP
by:
Anastasios Monachos
7,5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: BIG-IP
Affected Version From: 10.1.0
Affected Version To: 10.1.0
Patch Exists: Yes
Related CWE: CVE-2014-8727
CPE: a:f5:big-ip
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2014
F5 BIG-IP 10.1.0 – Directory Traversal Vulnerability
An authenticated user with either 'Resource Administrator' or 'Administrator' role privileges is able to arbitrary enumerate files and subsequently delete them off the OS level. In order to trigger the flaw, send a HTTP GET request similar to: https://<ip>/tmui/Control/jspmap/tmui/system/archive/properties.jsp?&name=../../../../../etc/passwd. If the file exists, the user can either send, a similar to, the next HTTP POST request or simply click on the Delete button through the GUI -the button will be displayed only if the enumerated file exists-.
Mitigation:
F5 Networks has released a security advisory and software updates to address this vulnerability.