28-03-2019 17:29:00
On BIG-IP ASM 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3, 13.0.0-, and 14.0.0-, there is a stored cross-site scripting vulnerability in an ASM violation viewed in the Configuration utility. In the worst case, an attacker can store a CSRF which results in code execution as the admin user.
28-03-2019 17:29:00
In Apache JSPWiki 2.9.0 to 2.11.0.M2, a carefully crafted URL could execute javascript on another user's session. No information could be saved on the server or jspwiki database, nor would an attacker be able to execute js on someone else's browser; only on its own browser.
28-03-2019 17:29:00
On BIG-IP 11.5.1-, 12.1.0-, 13.0.0-, and 14.0.0-, when processing certain SNMP requests with a request-id of 0, the snmpd process may leak a small amount of memory.
28-03-2019 17:29:00
On BIG-IP 11.5.1-11.5.8, 11.6.1-11.6.3, and 12.0.x, an undisclosed sequence of packets received by an SSL virtual server and processed by an associated Client SSL or Server SSL profile may cause a denial of service.
28-03-2019 17:29:00
On BIG-IP 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-, 13.0.0-, and 14.0.0-, under certain conditions, hardware systems with a High-Speed Bridge and using non-default Layer 2 forwarding configurations may experience a lockup of the High-Speed Bridge.