Vulnerability Name: CVE-2015-8021 (CCN-110014) Assigned: 2015-10-28 Published: 2016-01-20 Updated: 2016-11-28 Summary: Incomplete blacklist vulnerability in the Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, Link Controller, and PSM 11.x before 11.2.1 HF11, 11.3.x, 11.4.0 before HF8, and 11.4.1 before HF6; BIG-IP AAM 11.4.0 before HF8 and 11.4.1 before HF6; BIG-IP AFM and PEM 11.3.x, 11.4.0 before HF8, and 11.4.1 before HF6; and BIG-IP Edge Gateway, WebAccelerator, and WOM 11.x before 11.2.1 HF11 and 11.3.0 allows remote authenticated users to upload files via uploadImage.php. CVSS v3 Severity: 4.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N )3.8 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): LowUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): LowAvailibility (A): None
4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N )3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): LowUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): LowAvailibility (A): None
CVSS v2 Severity: 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): NoneIntegrity (I): PartialAvailibility (A): None
4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): NoneIntegrity (I): PartialAvailibility (A): None
Vulnerability Type: CWE-284 Vulnerability Consequences: Gain Access References: Source: MITRE Type: CNACVE-2015-8021 Source: BID Type: UNKNOWN82340 Source: CCN Type: BID-82340Multiple F5 BIG-IP Products CVE-2015-8021 Arbitrary File Upload Vulnerability Source: SECTRACK Type: UNKNOWN1034781 Source: XF Type: UNKNOWNf5-bigip-cve20158021-file-upload(110014) Source: CCN Type: F5 Security Advisory sol49580002BIG-IP file validation vulnerability CVE-2015-8021 Source: CONFIRM Type: Vendor Advisoryhttps://support.f5.com/kb/en-us/solutions/public/k/49/sol49580002.html Vulnerable Configuration: Configuration 1 :cpe:/a:f5:big-ip_access_policy_manager:11.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.3.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.4.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:11.3.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:11.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:11.4.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_analytics:11.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_analytics:11.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_analytics:11.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_analytics:11.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_analytics:11.3.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_analytics:11.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_analytics:11.4.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:11.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:11.4.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:11.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:11.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:11.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:11.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:11.3.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:11.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:11.4.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_edge_gateway:11.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_edge_gateway:11.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_edge_gateway:11.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_edge_gateway:11.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_edge_gateway:11.3.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:11.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:11.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:11.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:11.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:11.3.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:11.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:11.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:11.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:11.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:11.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:11.3.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:11.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:11.4.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.3.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.4.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:11.3.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:11.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:11.4.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:11.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:11.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:11.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:11.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:11.3.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:11.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:11.4.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_wan_optimization_manager:11.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_wan_optimization_manager:11.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_wan_optimization_manager:11.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_wan_optimization_manager:11.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_wan_optimization_manager:11.3.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:11.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:11.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:11.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:11.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:11.3.0:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:f5:big-ip_local_traffic_manager:11.5.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.5.3:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.3.0:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
f5 big-ip access policy manager 11.0.0
f5 big-ip access policy manager 11.1.0
f5 big-ip access policy manager 11.2.0
f5 big-ip access policy manager 11.2.1
f5 big-ip access policy manager 11.3.0
f5 big-ip access policy manager 11.4.0
f5 big-ip access policy manager 11.4.1
f5 big-ip advanced firewall manager 11.3.0
f5 big-ip advanced firewall manager 11.4.0
f5 big-ip advanced firewall manager 11.4.1
f5 big-ip analytics 11.0.0
f5 big-ip analytics 11.1.0
f5 big-ip analytics 11.2.0
f5 big-ip analytics 11.2.1
f5 big-ip analytics 11.3.0
f5 big-ip analytics 11.4.0
f5 big-ip analytics 11.4.1
f5 big-ip application acceleration manager 11.4.0
f5 big-ip application acceleration manager 11.4.1
f5 big-ip application security manager 11.0.0
f5 big-ip application security manager 11.1.0
f5 big-ip application security manager 11.2.0
f5 big-ip application security manager 11.2.1
f5 big-ip application security manager 11.3.0
f5 big-ip application security manager 11.4.0
f5 big-ip application security manager 11.4.1
f5 big-ip edge gateway 11.0.0
f5 big-ip edge gateway 11.1.0
f5 big-ip edge gateway 11.2.0
f5 big-ip edge gateway 11.2.1
f5 big-ip edge gateway 11.3.0
f5 big-ip global traffic manager 11.0.0
f5 big-ip global traffic manager 11.1.0
f5 big-ip global traffic manager 11.2.0
f5 big-ip global traffic manager 11.2.1
f5 big-ip global traffic manager 11.3.0
f5 big-ip global traffic manager 11.4.0
f5 big-ip link controller 11.0.0
f5 big-ip link controller 11.1.0
f5 big-ip link controller 11.2.0
f5 big-ip link controller 11.2.1
f5 big-ip link controller 11.3.0
f5 big-ip link controller 11.4.0
f5 big-ip link controller 11.4.1
f5 big-ip local traffic manager 11.0.0
f5 big-ip local traffic manager 11.1.0
f5 big-ip local traffic manager 11.2.0
f5 big-ip local traffic manager 11.2.1
f5 big-ip local traffic manager 11.3.0
f5 big-ip local traffic manager 11.4.0
f5 big-ip local traffic manager 11.4.1
f5 big-ip policy enforcement manager 11.3.0
f5 big-ip policy enforcement manager 11.4.0
f5 big-ip policy enforcement manager 11.4.1
f5 big-ip protocol security module 11.0.0
f5 big-ip protocol security module 11.1.0
f5 big-ip protocol security module 11.2.0
f5 big-ip protocol security module 11.2.1
f5 big-ip protocol security module 11.3.0
f5 big-ip protocol security module 11.4.0
f5 big-ip protocol security module 11.4.1
f5 big-ip wan optimization manager 11.0.0
f5 big-ip wan optimization manager 11.1.0
f5 big-ip wan optimization manager 11.2.0
f5 big-ip wan optimization manager 11.2.1
f5 big-ip wan optimization manager 11.3.0
f5 big-ip webaccelerator 11.0.0
f5 big-ip webaccelerator 11.1.0
f5 big-ip webaccelerator 11.2.0
f5 big-ip webaccelerator 11.2.1
f5 big-ip webaccelerator 11.3.0
f5 big-ip local traffic manager 11.5.1
f5 big-ip access policy manager 11.4.0
f5 big-ip local traffic manager 11.5.3
f5 big-ip local traffic manager 11.3.0