On version 14.1.x before 14.1.5.3, and all versions of 13...
High severity
Unreviewed
Published
Feb 1, 2023
to the GitHub Advisory Database
•
Updated Feb 17, 2023
Description
Published by the National Vulnerability Database
Feb 1, 2023
Published to the GitHub Advisory Database
Feb 1, 2023
Last updated
Feb 17, 2023
On version 14.1.x before 14.1.5.3, and all versions of 13.1.x, when the BIG-IP APM system is configured with all the following elements, undisclosed requests may cause the Traffic Management Microkernel (TMM) to terminate: * An OAuth Server that references an OAuth Provider * An OAuth profile with the Authorization Endpoint set to '/' * An access profile that references the above OAuth profile and is associated with an HTTPS virtual server Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References