ID

VAR-201604-0381


CVE

CVE-2015-8021


TITLE

plural F5 BIG-IP Product Configuration File upload vulnerability in the utility

Trust: 0.8

sources: JVNDB: JVNDB-2015-007049

DESCRIPTION

Incomplete blacklist vulnerability in the Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, Link Controller, and PSM 11.x before 11.2.1 HF11, 11.3.x, 11.4.0 before HF8, and 11.4.1 before HF6; BIG-IP AAM 11.4.0 before HF8 and 11.4.1 before HF6; BIG-IP AFM and PEM 11.3.x, 11.4.0 before HF8, and 11.4.1 before HF6; and BIG-IP Edge Gateway, WebAccelerator, and WOM 11.x before 11.2.1 HF11 and 11.3.0 allows remote authenticated users to upload files via uploadImage.php. plural F5 BIG-IP Product Configuration The utility contains a vulnerability where files are uploaded due to an incomplete blacklist. Supplementary information : CWE Vulnerability type by CWE-284: Improper Access Control ( Inappropriate access control ) Has been identified. http://cwe.mitre.org/data/definitions/284.htmlBy a remotely authenticated user uploadImage.php The file may be uploaded via. Multiple F5 BIG-IP products are prone to an arbitrary file-upload vulnerability. An attacker may leverage this issue to upload arbitrary files to the affected webserver; this can result in arbitrary code execution within the context of the vulnerable application. F5 BIG-IP LTM, etc. are all products of F5 Company in the United States. LTM is a local traffic manager; APM is a solution that provides secure unified access to business-critical applications and networks

Trust: 1.98

sources: NVD: CVE-2015-8021 // JVNDB: JVNDB-2015-007049 // BID: 82340 // VULHUB: VHN-85982

AFFECTED PRODUCTS

vendor:f5model:big-ip edge gatewayscope:eqversion:11.3.0

Trust: 1.8

vendor:f5model:big-ip wan optimization managerscope:eqversion:11.3.0

Trust: 1.8

vendor:f5model:big-ip webacceleratorscope:eqversion:11.3.0

Trust: 1.8

vendor:f5model:big-ip protocol security modulescope:eqversion:11.4.1

Trust: 1.6

vendor:f5model:big-ip protocol security modulescope:eqversion:11.2.0

Trust: 1.6

vendor:f5model:big-ip application security managerscope:eqversion:11.3.0

Trust: 1.6

vendor:f5model:big-ip webacceleratorscope:eqversion:11.0.0

Trust: 1.6

vendor:f5model:big-ip protocol security modulescope:eqversion:11.2.1

Trust: 1.6

vendor:f5model:big-ip application security managerscope:eqversion:11.0.0

Trust: 1.6

vendor:f5model:big-ip webacceleratorscope:eqversion:11.1.0

Trust: 1.6

vendor:f5model:big-ip protocol security modulescope:eqversion:11.4.0

Trust: 1.6

vendor:f5model:big-ip application security managerscope:eqversion:11.1.0

Trust: 1.6

vendor:f5model:big-ip webacceleratorscope:eqversion:11.2.0

Trust: 1.6

vendor:f5model:big-ip global traffic managerscope:eqversion:11.0.0

Trust: 1.0

vendor:f5model:big-ip wan optimization managerscope:eqversion:11.2.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.4.1

Trust: 1.0

vendor:f5model:big-ip analyticsscope:eqversion:11.0.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:11.1.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:eqversion:11.4.1

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.4.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:eqversion:11.1.0

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:eqversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.4.0

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:eqversion:11.0.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.0.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:11.4.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.4.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:11.2.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.0.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.4.1

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:eqversion:11.1.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:eqversion:11.2.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:eqversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.1.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:11.4.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.4.1

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:11.0.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:11.4.1

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.4.1

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.1.0

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:eqversion:11.2.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:11.0.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:11.1.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.2.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:11.4.1

Trust: 1.0

vendor:f5model:big-ip wan optimization managerscope:eqversion:11.0.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:11.1.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.4.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.2.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:11.2.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:11.2.0

Trust: 1.0

vendor:f5model:big-ip wan optimization managerscope:eqversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:eqversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip wan optimization managerscope:eqversion:11.1.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:11.4.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.4.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.4.1

Trust: 1.0

vendor:f5model:big-ip analyticsscope:eqversion:11.4.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.0.0 to 11.2.1 hf10

Trust: 0.8

vendor:f5model:big-ip access policy managerscope:eqversion:11.3.0 to 11.4.0 hf7

Trust: 0.8

vendor:f5model:big-ip access policy managerscope:eqversion:11.4.1 to 11.4.1 hf5

Trust: 0.8

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.3.0 to 11.4.0 hf7

Trust: 0.8

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.4.1 to 11.4.1 hf5

Trust: 0.8

vendor:f5model:big-ip analyticsscope:eqversion:11.0.0 to 11.2.1 hf10

Trust: 0.8

vendor:f5model:big-ip analyticsscope:eqversion:11.3.0 to 11.4.0 hf7

Trust: 0.8

vendor:f5model:big-ip analyticsscope:eqversion:11.4.1 to 11.4.1 hf5

Trust: 0.8

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.4.0 to 11.4.0 hf7

Trust: 0.8

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.4.1 to 11.4.1 hf5

Trust: 0.8

vendor:f5model:big-ip application security managerscope:eqversion:11.0.0 to 11.2.1 hf10

Trust: 0.8

vendor:f5model:big-ip application security managerscope:eqversion:11.3.0 to 11.4.0 hf7

Trust: 0.8

vendor:f5model:big-ip application security managerscope:eqversion:11.4.1 to 11.4.1 hf5

Trust: 0.8

vendor:f5model:big-ip edge gatewayscope:eqversion:11.0.0 to 11.2.1 hf10

Trust: 0.8

vendor:f5model:big-ip global traffic managerscope:eqversion:11.0.0 to 11.2.1 hf10

Trust: 0.8

vendor:f5model:big-ip global traffic managerscope:eqversion:11.3.0 to 11.4.0 hf7

Trust: 0.8

vendor:f5model:big-ip global traffic managerscope:eqversion:11.4.1 to 11.4.1 hf5

Trust: 0.8

vendor:f5model:big-ip link controllerscope:eqversion:11.0.0 to 11.2.1 hf10

Trust: 0.8

vendor:f5model:big-ip link controllerscope:eqversion:11.3.0 to 11.4.0 hf7

Trust: 0.8

vendor:f5model:big-ip link controllerscope:eqversion:11.4.1 to 11.4.1 hf5

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope:eqversion:11.0.0 to 11.2.1 hf10

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope:eqversion:11.3.0 to 11.4.0 hf7

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope:eqversion:11.4.1 to 11.4.1 hf5

Trust: 0.8

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.3.0 to 11.4.0 hf7

Trust: 0.8

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.4.1 to 11.4.1 hf5

Trust: 0.8

vendor:f5model:big-ip protocol security modulescope:eqversion:11.0.0 to 11.2.1 hf10

Trust: 0.8

vendor:f5model:big-ip protocol security modulescope:eqversion:11.3.0 to 11.4.0 hf7

Trust: 0.8

vendor:f5model:big-ip protocol security modulescope:eqversion:11.4.1 to 11.4.1 hf5

Trust: 0.8

vendor:f5model:big-ip wan optimization managerscope:eqversion:11.0.0 to 11.2.1 hf10

Trust: 0.8

vendor:f5model:big-ip webacceleratorscope:eqversion:11.0.0 to 11.2.1 hf10

Trust: 0.8

vendor:f5model:bigip webacceleratorscope:neversion:10.1

Trust: 0.3

vendor:f5model:bigip edgescope:neversion:10.1

Trust: 0.3

sources: BID: 82340 // JVNDB: JVNDB-2015-007049 // CNNVD: CNNVD-201602-079 // NVD: CVE-2015-8021

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-8021
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-8021
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201602-079
value: MEDIUM

Trust: 0.6

VULHUB: VHN-85982
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-8021
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-85982
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2015-8021
baseSeverity: MEDIUM
baseScore: 4.3
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 1.4
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-85982 // JVNDB: JVNDB-2015-007049 // CNNVD: CNNVD-201602-079 // NVD: CVE-2015-8021

PROBLEMTYPE DATA

problemtype:CWE-284

Trust: 1.1

problemtype:CWE-Other

Trust: 0.8

sources: VULHUB: VHN-85982 // JVNDB: JVNDB-2015-007049 // NVD: CVE-2015-8021

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201602-079

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201602-079

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-007049

PATCH

title:SOL49580002: BIG-IP file validation vulnerability CVE-2015-8021url:https://support.f5.com/kb/en-us/solutions/public/k/49/sol49580002.html

Trust: 0.8

title:Multiple F5 BIG-IP Fixes for product file upload vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=60066

Trust: 0.6

sources: JVNDB: JVNDB-2015-007049 // CNNVD: CNNVD-201602-079

EXTERNAL IDS

db:NVDid:CVE-2015-8021

Trust: 2.8

db:BIDid:82340

Trust: 2.0

db:SECTRACKid:1034781

Trust: 1.7

db:JVNDBid:JVNDB-2015-007049

Trust: 0.8

db:CNNVDid:CNNVD-201602-079

Trust: 0.6

db:VULHUBid:VHN-85982

Trust: 0.1

sources: VULHUB: VHN-85982 // BID: 82340 // JVNDB: JVNDB-2015-007049 // CNNVD: CNNVD-201602-079 // NVD: CVE-2015-8021

REFERENCES

url:http://www.securityfocus.com/bid/82340

Trust: 1.7

url:https://support.f5.com/kb/en-us/solutions/public/k/49/sol49580002.html

Trust: 1.7

url:http://www.securitytracker.com/id/1034781

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-8021

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-8021

Trust: 0.8

url:http://www.f5.com/products/big-ip/

Trust: 0.3

sources: VULHUB: VHN-85982 // BID: 82340 // JVNDB: JVNDB-2015-007049 // CNNVD: CNNVD-201602-079 // NVD: CVE-2015-8021

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 82340

SOURCES

db:VULHUBid:VHN-85982
db:BIDid:82340
db:JVNDBid:JVNDB-2015-007049
db:CNNVDid:CNNVD-201602-079
db:NVDid:CVE-2015-8021

LAST UPDATE DATE

2024-11-23T22:30:59.692000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-85982date:2016-11-28T00:00:00
db:BIDid:82340date:2016-07-05T21:20:00
db:JVNDBid:JVNDB-2015-007049date:2016-04-19T00:00:00
db:CNNVDid:CNNVD-201602-079date:2016-04-13T00:00:00
db:NVDid:CVE-2015-8021date:2024-11-21T02:37:51.457

SOURCES RELEASE DATE

db:VULHUBid:VHN-85982date:2016-04-12T00:00:00
db:BIDid:82340date:2016-01-20T00:00:00
db:JVNDBid:JVNDB-2015-007049date:2016-04-19T00:00:00
db:CNNVDid:CNNVD-201602-079date:2016-01-20T00:00:00
db:NVDid:CVE-2015-8021date:2016-04-12T14:59:02.177