HIGH

CVE-2023-46748

F5 Big Ip Access Policy Manager 2023-10-26 CVSS v3.1
CVSS
8.8
KEV

Description

An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which

may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands.

 Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Summary dbcve.org

Authenticated SQL injection in BIG-IP Configuration utility allows attackers with valid credentials and network access to the management interface to execute arbitrary system commands. The vulnerability stems from improper input handling in the configuration utility, enabling SQL queries to be injected through vulnerable parameters.

Mitigation

Apply the vendor-supplied patch for BIG-IP versions still under support; restrict management interface access to trusted networks only and enforce strong authentication policies.

Proof of Concept

Weakness (CWE)

CWE-89 SQL Injection

EPSS Score

4.47%
Probability of exploitation in next 30 days
91th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE