CVE-2022-29263High· 7.8▾ TwilightOn F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, as well as F5 BIG-IP APM Clients 7.x versio…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, as well as F5 BIG-IP APM Clients 7.x versions prior to 7.2.1.5, the BIG-IP Edge Client Component Installer Service does not use best practice while saving temporary files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
access_policy_manager_clients = 7.1.8access_policy_manager_clients = 7.1.8.5access_policy_manager_clients = 7.1.9access_policy_manager_clients = 7.1.9.7access_policy_manager_clients = 7.1.9.8access_policy_manager_clients = 7.2.1access_policy_manager_clients = 7.2.1.1big-ip_access_policy_manager = 11.6.1big-ip_access_policy_manager = 11.6.2big-ip_access_policy_manager = 11.6.3big-ip_access_policy_manager = 11.6.4big-ip_access_policy_manager = 11.6.5big-ip_access_policy_manager = 12.1.0big-ip_access_policy_manager = 12.1.1big-ip_access_policy_manager = 12.1.2big-ip_access_policy_manager = 12.1.3big-ip_access_policy_manager = 12.1.4big-ip_access_policy_manager = 12.1.5big-ip_access_policy_manager = 12.1.6big-ip_access_policy_manager = 13.1.0big-ip_access_policy_manager = 13.1.1big-ip_access_policy_manager = 13.1.3big-ip_access_policy_manager = 13.1.4big-ip_access_policy_manager = 13.1.5big-ip_access_policy_manager = 14.1.0big-ip_access_policy_manager = 14.1.2big-ip_access_policy_manager = 14.1.3big-ip_access_policy_manager = 14.1.4big-ip_access_policy_manager = 15.1.0big-ip_access_policy_manager = 15.1.1big-ip_access_policy_manager = 15.1.2big-ip_access_policy_manager = 15.1.3big-ip_access_policy_manager = 15.1.4big-ip_access_policy_manager = 15.1.5big-ip_access_policy_manager = 16.1.0big-ip_access_policy_manager = 16.1.1big-ip_access_policy_manager = 16.1.2big-ip_access_policy_manager = 17.0.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2018-1115Critical· 9.1postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile
CVE-2020-10781Medium· 5.5A flaw was found in the Linux Kernel before 5.8-rc6 in the ZRAM kernel module, where a user with a local account and the ability to read the /sys/class/zram-control/hot_add file can create ZRAM device nodes in the /dev/ directory
CVE-2025-54546High· 7.5On affected platforms, restricted users could use SSH port forwarding to access host-internal services
CVE-2025-54545High· 7.8On affected platforms, a restricted user could break out of the CLI sandbox to the system shell and elevate their privileges.
CVE-2025-43470Medium· 5.5A permissions issue was addressed with additional restrictions
CVE-2026-10840High· 7.1A flaw was found in the OpenShift Pipelines operator