CVE-2023-46748
Description
An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which
may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Summary dbcve.org
Authenticated SQL injection in BIG-IP Configuration utility allows attackers with valid credentials and network access to the management interface to execute arbitrary system commands. The vulnerability stems from improper input handling in the configuration utility, enabling SQL queries to be injected through vulnerable parameters.
Mitigation
Apply the vendor-supplied patch for BIG-IP versions still under support; restrict management interface access to trusted networks only and enforce strong authentication policies.