CVE-2023-22341

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
01/02/2023
Last modified:
07/11/2023

Description

On version 14.1.x before 14.1.5.3, and all versions of 13.1.x, when the BIG-IP APM system is configured with all the following elements, undisclosed requests may cause the Traffic Management Microkernel (TMM) to terminate:<br /> <br /> * An OAuth Server that references an OAuth Provider<br /> * An OAuth profile with the Authorization Endpoint set to &amp;#39;/&amp;#39;<br /> * An access profile that references the above OAuth profile and is associated with an HTTPS virtual server <br /> <br /> <br /> Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.<br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* 13.1.0 (including) 13.1.5 (including)
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* 14.1.0 (including) 14.1.5.3 (excluding)


References to Advisories, Solutions, and Tools