CVE-2022-26890

On F5 BIG-IP Advanced WAF, ASM, and APM 16.1.x versions prior to 16.1.2.1, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when ASM or Advanced WAF, as well as APM, are configured on a virtual server, the ASM policy is configured with Session Awareness, and the "Use APM Username and Session ID" option is enabled, undisclosed requests can cause the bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
f5CNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
VendorProductVersion
f5big-ip_access_policy_manager
13.1.0
f5big-ip_access_policy_manager
13.1.1
f5big-ip_access_policy_manager
13.1.3
f5big-ip_access_policy_manager
13.1.4
f5big-ip_access_policy_manager
13.1.5
f5big-ip_access_policy_manager
14.1.0
f5big-ip_access_policy_manager
14.1.2
f5big-ip_access_policy_manager
14.1.3
f5big-ip_access_policy_manager
14.1.4
f5big-ip_access_policy_manager
15.1.0
f5big-ip_access_policy_manager
15.1.1
f5big-ip_access_policy_manager
15.1.2
f5big-ip_access_policy_manager
15.1.3
f5big-ip_access_policy_manager
15.1.4
f5big-ip_access_policy_manager
15.1.5
f5big-ip_access_policy_manager
16.1.0
f5big-ip_access_policy_manager
16.1.1
f5big-ip_access_policy_manager
16.1.2
f5big-ip_advanced_web_application_firewall
13.1.0
f5big-ip_advanced_web_application_firewall
13.1.1
f5big-ip_advanced_web_application_firewall
13.1.3
f5big-ip_advanced_web_application_firewall
13.1.4
f5big-ip_advanced_web_application_firewall
13.1.5
f5big-ip_advanced_web_application_firewall
14.1.0
f5big-ip_advanced_web_application_firewall
14.1.2
f5big-ip_advanced_web_application_firewall
14.1.3
f5big-ip_advanced_web_application_firewall
14.1.4
f5big-ip_advanced_web_application_firewall
15.1.0
f5big-ip_advanced_web_application_firewall
15.1.1
f5big-ip_advanced_web_application_firewall
15.1.2
f5big-ip_advanced_web_application_firewall
15.1.3
f5big-ip_advanced_web_application_firewall
15.1.4
f5big-ip_advanced_web_application_firewall
15.1.5
f5big-ip_advanced_web_application_firewall
16.1.0
f5big-ip_advanced_web_application_firewall
16.1.1
f5big-ip_advanced_web_application_firewall
16.1.2
f5big-ip_application_security_manager
13.1.0
f5big-ip_application_security_manager
13.1.1
f5big-ip_application_security_manager
13.1.3
f5big-ip_application_security_manager
13.1.4
f5big-ip_application_security_manager
13.1.5
f5big-ip_application_security_manager
14.1.0
f5big-ip_application_security_manager
14.1.2
f5big-ip_application_security_manager
14.1.3
f5big-ip_application_security_manager
14.1.4
f5big-ip_application_security_manager
15.1.0
f5big-ip_application_security_manager
15.1.1
f5big-ip_application_security_manager
15.1.2
f5big-ip_application_security_manager
15.1.3
f5big-ip_application_security_manager
15.1.4
f5big-ip_application_security_manager
15.1.5
f5big-ip_application_security_manager
16.1.0
f5big-ip_application_security_manager
16.1.1
f5big-ip_application_security_manager
16.1.2
𝑥
= Vulnerable software versions