CVE Published: 20/12/2018 |
CVE Updated: 16/09/2024 |
CVE Year: 2018 Source: f5 |
Vendor: F5 Networks, Inc. |
Product: BIG-IP (AAM) Status : PUBLISHED
CVE-2018-15331 Description
On BIG-IP AAM 13.0.0 or 12.1.0-12.1.3.7, the dcdb_convert utility used by BIG-IP AAM fails to drop group permissions when executing helper scripts, which could be used to leverage attacks against the BIG-IP system.