
Cloud Vulnerability DB
A community-led vulnerabilities database
On BIG-IP versions 15.0.0-15.0.1, 14.1.0-14.1.2.3, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, when a virtual server is configured with HTTP explicit proxy and has an attached HTTP_PROXY_REQUEST iRule, POST requests sent to the virtual server cause an xdata memory leak (CVE Details).
The vulnerability affects BIG-IP systems when configured with specific conditions: a virtual server using HTTP explicit proxy configuration along with an HTTP_PROXY_REQUEST iRule. When these conditions are met, POST requests to the virtual server trigger an xdata memory leak (F5 Support).
The primary impact of this vulnerability is a memory leak in the system, which could potentially lead to degraded performance or system instability over time if left unaddressed (CVE Details).
The vulnerability requires specific configuration conditions to be exploitable: the system must have a virtual server configured with HTTP explicit proxy and an HTTP_PROXY_REQUEST iRule. The exploit is triggered by sending POST requests to the affected virtual server (F5 Support).
F5 has released patches for the affected versions. Users should upgrade to a patched version of BIG-IP to address this vulnerability (F5 Support).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."