CVE Database
/

CVE-2021-23014

Back to search

CVE-2021-23014

Published: May 10, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, and 14.1.x before 14.1.4, BIG-IP Advanced WAF and ASM are missing authorization checks for file uploads to a specific directory within the REST API which might allow Authenticated users with guest privileges to upload files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

VendorProductVersions

n/a

BIG-IP ASM/Advanced WAF

affected
16.0.x before 16.0.1.1, 15.1.x before 15.1.3, and 14.1.x before 14.1.4

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now