CVE-2008-6474
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
16/03/2009
Last modified:
09/04/2025
Description
The management interface in F5 BIG-IP 9.4.3 allows remote authenticated users with Resource Manager privileges to inject arbitrary Perl code via unspecified configuration settings related to Perl EP3 with templates, probably triggering static code injection.
Impact
Base Score 2.0
9.00
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:f5:tmos:9.4.3:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://osvdb.org/51116
- http://www.securityfocus.com/archive/1/490496/100/0/threaded
- http://www.securityfocus.com/bid/28639
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49308
- http://osvdb.org/51116
- http://www.securityfocus.com/archive/1/490496/100/0/threaded
- http://www.securityfocus.com/bid/28639
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49308