漏洞类别:Local
漏洞等级:
漏洞信息
The Configuration Utility implemented in vulnerable versions of F5 BIG-IP ASM fails to properly validate user-supplied input. A remote authenticated user can supply a specially crafted request to view files on the target system that are located within the web root directory.
Affected Versions:
BIG-IP ASM 11.0.0 - 11.6.0 BIG-IP ASM 10.1.0 - 10.2.4
漏洞危害
Successful exploitation allows an authenticated, remote attacker to gain an unauthorized access to files located within the web root.
解决方案
0day
文章评论