CVE-2020-5880

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
30/04/2020
Last modified:
07/05/2020

Description

Om BIG-IP 15.0.0-15.0.1.3 and 14.1.0-14.1.2.3, the restjavad process may expose a way for attackers to upload arbitrary files on the BIG-IP system, bypassing the authorization system. Resulting error messages may also reveal internal paths of the server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* 14.1.0 (including) 14.1.2.3 (including)
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* 15.0.0 (including) 15.0.1.3 (including)
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* 14.1.0 (including) 14.1.2.3 (including)
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* 15.0.0 (including) 15.0.1.3 (including)
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:* 14.1.0 (including) 14.1.2.3 (including)
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:* 15.0.0 (including) 15.0.1.3 (including)
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* 14.1.0 (including) 14.1.2.3 (including)
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* 15.0.0 (including) 15.0.1.3 (including)
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* 14.1.0 (including) 14.1.2.3 (including)
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* 15.0.0 (including) 15.0.1.3 (including)
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:* 14.1.0 (including) 14.1.2.3 (including)
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:* 15.0.0 (including) 15.0.1.3 (including)
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:* 14.1.0 (including) 14.1.2.3 (including)
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:* 15.0.0 (including) 15.0.1.3 (including)
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:* 14.1.0 (including) 14.1.2.3 (including)


References to Advisories, Solutions, and Tools