F5 BIG-IP Local Traffic Manager 9.4.7

CPE Details

F5 BIG-IP Local Traffic Manager 9.4.7
9.4.7
2019-02-27
13h11 +00:00
2019-02-27
13h11 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:f5:big-ip_local_traffic_manager:9.4.7:*:*:*:*:*:*:*

Informations

Vendor

f5

Product

big-ip_local_traffic_manager

Version

9.4.7

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2013-3587 2020-02-21 16h11 +00:00 The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which makes it easier for man-in-the-middle attackers to obtain plaintext secret values by observing length differences during a series of guesses in which a string in an HTTP request URL potentially matches an unknown string in an HTTP response body, aka a "BREACH" attack, a different issue than CVE-2012-4929.
5.9
Medium
CVE-2015-4040 2015-09-17 14h00 +00:00 Directory traversal vulnerability in the configuration utility in F5 BIG-IP before 12.0.0 and Enterprise Manager 3.0.0 through 3.1.1 allows remote authenticated users to access arbitrary files in the web root via unspecified vectors.
4
CVE-2014-8727 2014-11-17 15h00 +00:00 Multiple directory traversal vulnerabilities in F5 BIG-IP before 10.2.2 allow local users with the "Resource Administrator" or "Administrator" role to enumerate and delete arbitrary files via a .. (dot dot) in the name parameter to (1) tmui/Control/jspmap/tmui/system/archive/properties.jsp or (2) tmui/Control/form.
6.2
CVE-2012-1493 2012-07-09 22h00 +00:00 F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2, 2.2.x before 2.2.0-HF1, and 2.3.x before 2.3.0-HF3, use a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins via the PubkeyAuthentication option.
7.8