2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2015-8021" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2016-04-12T14:59:02.177" ,
"lastModified" : "2016-11-28T19:45:22.523" ,
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Incomplete blacklist vulnerability in the Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, Link Controller, and PSM 11.x before 11.2.1 HF11, 11.3.x, 11.4.0 before HF8, and 11.4.1 before HF6; BIG-IP AAM 11.4.0 before HF8 and 11.4.1 before HF6; BIG-IP AFM and PEM 11.3.x, 11.4.0 before HF8, and 11.4.1 before HF6; and BIG-IP Edge Gateway, WebAccelerator, and WOM 11.x before 11.2.1 HF11 and 11.3.0 allows remote authenticated users to upload files via uploadImage.php."
} ,
{
"lang" : "es" ,
"value" : "Vulnerabilidad de lista negra incompleta en la utilidad Configuration en F5 BIG-IP LTM, Analytics, APM, ASM, GTM, Link Controller y PSM 11.x en versiones anteriores a 11.2.1 HF11, 11.3.x, 11.4.0 en versiones anteriores a HF8 y 11.4.1 en versiones anteriores a HF6; BIG-IP AAM 11.4.0 en versiones anteriores a HF8 y 11.4.1 en versiones anteriores a HF6; BIG-IP AFM y PEM 11.3.x, 11.4.0 en versiones anteriores a HF8 y 11.4.1 en versiones anteriores a HF6 y BIG-IP Edge Gateway, WebAccelerator y WOM 11.x en versiones anteriores a 11.2.1 HF11 y 11.3.0 permite a usuarios remotos autenticados cargar archivos a trav\u00e9s de uploadImage.php."
}
] ,
"metrics" : {
"cvssMetricV30" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.0" ,
"vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "LOW" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 4.3 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 1.4
}
] ,
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:N" ,
"accessVector" : "NETWORK" ,
"accessComplexity" : "LOW" ,
"authentication" : "SINGLE" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "PARTIAL" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 4.0
} ,
"baseSeverity" : "MEDIUM" ,
"exploitabilityScore" : 8.0 ,
"impactScore" : 2.9 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-284"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_access_policy_manager:11.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DD575B3E-FBA9-443A-9B52-49766DBE40C4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_access_policy_manager:11.1.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F8F3BF3A-DC42-45F4-99C0-DF71DB1A9E44"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_access_policy_manager:11.2.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "002333F5-2864-434F-AC94-9C644098F95C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_access_policy_manager:11.2.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FB630A86-FB84-4199-9E4D-38EB620806CB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_access_policy_manager:11.3.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "ABF47456-CCA0-4817-9AEF-631DC152174E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_access_policy_manager:11.4.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FB5F9107-549C-40EF-B355-C7E93A979CDD"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_access_policy_manager:11.4.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B1A1C200-30B2-4B38-BC74-D11E54530A96"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.3.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7507BDFF-5B52-4A06-9F8C-2B6F3958162A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.4.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6E0141FA-44E9-460E-B175-29A7FA251301"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.4.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8DD27EF7-3329-4009-959F-D2E4D5935E57"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_analytics:11.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8FA5C323-7247-42B5-AF3E-F7E8A18932CD"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_analytics:11.1.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FF199950-9564-4CF2-BC74-F9E1C28AC377"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_analytics:11.2.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A613D29A-9C7F-49A5-98E4-8477A1FF7C9E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_analytics:11.2.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "867B2CA9-DAE5-4070-B8E6-F624C59F5054"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_analytics:11.3.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "52CD200C-1D14-471F-93C1-027CC676C26C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_analytics:11.4.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4D1850CE-D20D-4677-8CF2-1DB3A4EB33F2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_analytics:11.4.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0A70B1E2-0B3D-4DE9-8ED9-777F73D0B750"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_application_acceleration_manager:11.4.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "974C5213-99F7-4E8A-AC6A-8759697F19C4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_application_acceleration_manager:11.4.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E288D50B-7EFA-4FC8-938B-EE3765FFA24D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_application_security_manager:11.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "094BD2B6-E269-4647-A77C-B584805B6203"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_application_security_manager:11.1.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "45C31572-6C40-4621-AB57-6768DE0D59A3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_application_security_manager:11.2.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4617DC7B-07BA-4805-9789-CFDBA8535214"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_application_security_manager:11.2.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A635FEC4-4F52-4971-A67D-47E68108E4F4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_application_security_manager:11.3.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "EC69B41E-C22D-48D2-8609-60C018F1F48D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_application_security_manager:11.4.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "270EEBF6-46FA-48FC-BEC9-9C0838A86BB4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_application_security_manager:11.4.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "93310708-E1FE-445A-BB1F-7D1F553AEC65"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_edge_gateway:11.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "53531CA7-5E47-4C46-BDA5-3B4710085078"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_edge_gateway:11.1.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5A085285-329B-4EF0-ABFB-238655E9E82D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_edge_gateway:11.2.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1591F627-3C86-4904-9236-6936D533ED75"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_edge_gateway:11.2.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3136A8D1-3D0D-46B3-9A3A-737074864F1B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_edge_gateway:11.3.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "96673865-3D37-4562-831E-3ACE9DFB471E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_global_traffic_manager:11.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9AA7DCB7-D01E-492A-A810-01B15F03A783"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_global_traffic_manager:11.1.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E7F8D9A5-0C91-4458-8554-13947FD8B116"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_global_traffic_manager:11.2.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B171AA24-6500-43D8-9167-BA9BA57682E5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_global_traffic_manager:11.2.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "84452450-77FA-4708-9C86-5464D541C8ED"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_global_traffic_manager:11.3.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A49B1D82-3EC2-4E20-8FF5-58248905E964"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_global_traffic_manager:11.4.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7E4CC3E0-F9B8-433F-A2B0-2306144F9B6A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_link_controller:11.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4C2FFC93-7053-441C-AD96-ED57F97E9A70"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_link_controller:11.1.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "792625FF-276B-4972-8915-4571C9E26BF5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_link_controller:11.2.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "EE20D0B7-E96B-448E-B80D-0D596248B410"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_link_controller:11.2.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2DD53088-3BD4-4AF9-8934-4905231A75E8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_link_controller:11.3.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C4CB61D3-DF59-4EE0-A0F0-5899850496B9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_link_controller:11.4.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FF646EF0-56C8-492E-A78D-B00ECAA8D851"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_link_controller:11.4.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0D42B922-A5F7-41FC-A361-BA0E065B5B00"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_local_traffic_manager:11.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C72FF118-E7A5-42DE-A9A0-703E71615045"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_local_traffic_manager:11.1.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "45A53EC8-8E16-42DC-9FD8-58493C5D1EC5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_local_traffic_manager:11.2.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DDB299B4-5893-4D91-8E5B-09BDFDB86FEF"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_local_traffic_manager:11.2.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F9EA336A-8055-4DA8-8F79-07C4ADE83E32"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_local_traffic_manager:11.3.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "624EFAEB-15C2-422F-BAD1-D0BC37878349"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_local_traffic_manager:11.4.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "76C1525D-46DE-4362-BBAD-095BBF718990"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_local_traffic_manager:11.4.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "259C05BB-6349-4005-9372-21623DC5002D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.3.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3CA52816-C4B7-4B1E-A950-EE9B571CB06B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.4.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F2AA5127-5314-4026-905D-937B7B62473F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.4.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "09E42DAA-700D-487C-9238-F7F3D75A8C1A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_protocol_security_module:11.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3251DB7F-0436-48D5-AF7B-F812237DB926"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_protocol_security_module:11.1.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8600FF27-4407-4755-A1E3-5648D9ACCB1C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_protocol_security_module:11.2.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D3A84AF1-A18E-4AFD-B85E-49CE46A548D8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_protocol_security_module:11.2.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BA54B88F-4A16-4F40-8A3B-B107F0CA2334"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_protocol_security_module:11.3.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "17C28542-51A4-4464-ADF9-C6376F829F4A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_protocol_security_module:11.4.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "584853F9-644F-40B2-A28F-1CE9B51F84F6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_protocol_security_module:11.4.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DFE665CF-A633-474E-9519-D20E3D3958CF"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_wan_optimization_manager:11.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C14D0DD3-E6A9-43C8-85D7-6DBB16E30DD5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_wan_optimization_manager:11.1.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2B59396A-EAFF-41D4-874F-4CA91D901807"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_wan_optimization_manager:11.2.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4C9C14C5-B23C-4CE3-8FF0-52741CBB602E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_wan_optimization_manager:11.2.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7FBA20ED-08F5-4C35-991A-0DBC6BEAECC7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_wan_optimization_manager:11.3.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8D94751C-A340-4DE7-821A-5143FA0011E4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_webaccelerator:11.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E5E8E654-DA20-45F9-A25E-44D1E31F64C6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_webaccelerator:11.1.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3C8FCFDA-703B-42DC-91FF-00066E88E49D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_webaccelerator:11.2.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3CA49611-A8E4-454E-98AD-B64C0202838F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_webaccelerator:11.2.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FF7FCC81-2F1D-4EF5-956B-085FB7FEFAE7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:f5:big-ip_webaccelerator:11.3.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "200A9CE9-E56D-4EFA-AC8A-954F945DDDBB"
}
]
}
]
}
] ,
"references" : [
{
"url" : "http://www.securityfocus.com/bid/82340" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://www.securitytracker.com/id/1034781" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://support.f5.com/kb/en-us/solutions/public/k/49/sol49580002.html" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Vendor Advisory"
]
}
]
}