CVE-2021-23016

MEDIUM

BIG-IP APM <16.0.x, 12.1.x, 11.6.x - Auth Bypass

Title source: llm
STIX 2.1

Description

On BIG-IP APM versions 15.1.x before 15.1.3, 14.1.x before 14.1.4.1, 13.1.x before 13.1.4, and all versions of 16.0.x, 12.1.x, and 11.6.x, an attacker may be able to bypass APM's internal restrictions and retrieve static content that is hosted within APM by sending specifically crafted requests to an APM Virtual Server. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://support.f5.com/csp/article/K75540265

Scores

CVSS v3 5.3
EPSS 0.0026
EPSS Percentile 49.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

Status published
Products (1)
f5/big-ip_access_policy_manager 11.6.1 - 11.6.5
Published May 10, 2021
Tracked Since Feb 18, 2026