CVE Published: 13/09/2018 |
CVE Updated: 16/09/2024 |
CVE Year: 2018 Source: f5 |
Vendor: F5 Networks, Inc. |
Product: BIG-IP APM Status : PUBLISHED
CVE-2018-5548 Description
On BIG-IP APM 11.6.0-11.6.3, an insecure AES ECB mode is used for orig_uri parameter in an undisclosed /vdesk link of APM virtual server configured with an access profile, allowing a malicious user to build a redirect URI value using different blocks of cipher texts.