CVE-2025-47148Medium· 6.5▾ SunlitWhen the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with single logout (SLO) enabled on an access policy, undisclosed requests can cause an increase …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with single logout (SLO) enabled on an access policy, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
big-ip_access_policy_manager >= 15.1.0, < 15.1.10.8big-ip_access_policy_manager >= 16.1.0, < 16.1.6.1big-ip_access_policy_manager >= 17.1.0, < 17.1.3big-ip_access_policy_manager = 17.5.0big-ip_ssl_orchestrator >= 15.1.0, < 15.1.10.8big-ip_ssl_orchestrator >= 16.1.0, < 16.1.6.1big-ip_ssl_orchestrator >= 17.1.0, < 17.1.3big-ip_ssl_orchestrator = 17.5.0Upgrade past the affected range:
big-ip_access_policy_manager 17.1.3big-ip_ssl_orchestrator 17.1.3Connected by shared product, vendor, weakness, or advisory.
CVE-2025-61933Medium· 6.1A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of BIG-IP APM that allows an attacker to run JavaScript in the context of the targeted logged-out user. Note: Software versions which have reached End of…
CVE-2025-61951High· 7.5Undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. This issue may occur when a Datagram Transport Layer Security (DTLS) 1.2 virtual server is enabled with a Server SSL profile that is configured with a …
CVE-2025-61960High· 7.5When a per-request policy is configured on a BIG-IP APM portal access virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Suppo…
CVE-2025-59269Medium· 6.1A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions whic…
CVE-2025-59481High· 8.7A vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with at least resource administrator role to execute arbitrary system commands with higher privileges. …
CVE-2025-59483Medium· 6.5A validation vulnerability exists in an undisclosed URL in the Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.