F5 BIG-IP LTM等都是美国F5公司的产品。LTM是一款本地流量管理器;APM是一套提供安全统一访问关键业务应用和网络的解决方案。 多款F5产品的iControl API中存在安全漏洞,该漏洞源于iControl/iControlPortal.cgi文件没有充分过滤SOAP请求。远程攻击者可借助iCall脚本或处理程序利用该漏洞以‘Resource Administrator’角色获取权限。以下产品及版本受到影响:F5 BIG-IP LTM,AFM,Analytics,APM,ASM,Link C
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2015-3276 | OpenLDAP 加密问题漏洞 | |
| CVE-2015-1342 | LXCFS 安全漏洞 | |
| CVE-2015-1344 | LXCFS 安全漏洞 | |
| CVE-2015-4334 | Blue Coat Systems ProxySG SGOS 安全漏洞 | |
| CVE-2015-5006 | IBM Java SDK 信息泄露漏洞 | |
| CVE-2015-5309 | PuTTY 整数溢出漏洞 | |
| CVE-2015-7348 | zTree 跨站脚本漏洞 | |
| CVE-2015-8084 | 多款Huawei产品拒绝服务漏洞 | |
| CVE-2015-8124 | Sensio Labs Symfony 会话固定漏洞 | |
| CVE-2015-8125 | Sensio Labs Symfony 安全漏洞 | |
| CVE-2015-8131 | Elasticsearch Kibana 跨站请求伪造漏洞 | |
| CVE-2015-8213 | Django 安全漏洞 | |
| CVE-2015-8482 | Blue Coat Systems Unified Agent 安全漏洞 | |
| CVE-2015-5273 | Automatic Bug Reporting Tool 后置链接漏洞 | |
| CVE-2015-5287 | Red Hat Automatic Bug Reporting Tool 安全漏洞 | |
| CVE-2015-5302 | libreport 信息泄露漏洞 |
No comments yet