← Back to CVE List
Vulnerability Intelligence Report

CVE-2013-0150

Directory traversal vulnerability in an unspecified signed Java applet in the client-side components in F5 BIG-IP APM 10.1.0 through 10.2.4 and 11.0.0 through 11.3.0, FirePass 6.0.0 through 6.1.0 and 7.0.0, and other products "when APM is provisioned," allows remote attackers to upload and execute arbitrary files via a .. (dot dot) in the filename parameter.

No Active Exploit Signals
CVSS Base Score
9.3
HIGH
EPSS Probability:6.32%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
f5 big-ip_access_policy_manager all
f5 big-ip_advanced_firewall_manager 11.3.0
f5 big-ip_analytics all
f5 big-ip_application_security_manager all
f5 big-ip_edge_gateway all
f5 big-ip_global_traffic_manager all
f5 big-ip_link_controller all
f5 big-ip_local_traffic_manager all
f5 big-ip_policy_enforcement_manager 11.3.0
f5 big-ip_protocol_security_module all
f5 big-ip_wan_optimization_manager all
f5 big-ip_webaccelerator all
f5 firepass 7.0.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
6.316%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCERT/CC · CERT · USA
Reserved2012-12-06T00:00:00
Published2013-08-09T18:00:00
Last Updated2024-09-16T18:29:34

LINK COPIED TO CLIPBOARD