CVE-2018-5548

On BIG-IP APM 11.6.0-11.6.3, an insecure AES ECB mode is used for orig_uri parameter in an undisclosed /vdesk link of APM virtual server configured with an access profile, allowing a malicious user to build a redirect URI value using different blocks of cipher texts.
References
Configurations

Configuration 1

cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*

Information

Published : 2018-09-13 02:29

Updated : 2018-12-03 02:37


NVD link : CVE-2018-5548

Mitre link : CVE-2018-5548

Products Affected
No products.
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')