The Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, and Link Controller 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP AAM 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP AFM and PEM 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP Edge Gateway, WebAccelerator, and WOM 11.x before 11.2.1 HF16 and 11.3.0; and BIG-IP PSM 11.x before 11.2.1 HF16, 11.3.x, and 11.4.x before 11.4.1 HF10 allows remote authenticated users with certain permissions to gain privileges by leveraging an Access Policy Manager customization configuration section that allows file uploads.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.securitytracker.com/id/1036627 | Third Party Advisory VDB Entry | 
| https://support.f5.com/kb/en-us/solutions/public/k/12/sol12401251.html | Vendor Advisory | 
| http://www.securitytracker.com/id/1036627 | Third Party Advisory VDB Entry | 
| https://support.f5.com/kb/en-us/solutions/public/k/12/sol12401251.html | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
            
            
  | 
    
Configuration 2 (hide)
            
            
  | 
    
Configuration 3 (hide)
            
            
  | 
    
Configuration 4 (hide)
            
            
  | 
    
Configuration 5 (hide)
            
            
  | 
    
Configuration 6 (hide)
            
            
  | 
    
Configuration 7 (hide)
            
            
  | 
    
Configuration 8 (hide)
            
            
  | 
    
Configuration 9 (hide)
            
            
  | 
    
Configuration 10 (hide)
            
            
  | 
    
Configuration 11 (hide)
            
            
  | 
    
Configuration 12 (hide)
            
            
  | 
    
Configuration 13 (hide)
            
            
  | 
    
Configuration 14 (hide)
            
            
  | 
    
History
                    21 Nov 2024, 02:37
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://www.securitytracker.com/id/1036627 - Third Party Advisory, VDB Entry | |
| References | () https://support.f5.com/kb/en-us/solutions/public/k/12/sol12401251.html - Vendor Advisory | 
Information
                Published : 2016-08-19 21:59
Updated : 2025-04-12 10:46
NVD link : CVE-2015-8022
Mitre link : CVE-2015-8022
CVE.ORG link : CVE-2015-8022
JSON object : View
Products Affected
                f5
- big-ip_local_traffic_manager
 - big-ip_application_security_manager
 - big-ip_websafe
 - big-ip_protocol_security_module
 - big-ip_edge_gateway
 - big-ip_policy_enforcement_manager
 - big-ip_link_controller
 - big-ip_application_acceleration_manager
 - big-ip_global_traffic_manager
 - big-ip_advanced_firewall_manager
 - big-ip_analytics
 - big-ip_access_policy_manager
 - big-ip_wan_optimization_manager
 - big-ip_webaccelerator
 
CWE
                
                    
                        
                        CWE-264
                        
            Permissions, Privileges, and Access Controls
