Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2023-22341

On version 14.1.x before 14.1.5.3, and all versions of 13.1.x, when the BIG-IP APM system is configured with all the following elements, undisclosed requests may cause the Traffic Management Microkernel (TMM) to terminate:

  • An OAuth Server that references an OAuth Provider
  • An OAuth profile with the Authorization Endpoint set to '/'
  • An access profile that references the above OAuth profile and is associated with an HTTPS virtual server

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • Published: Feb 1, 2023
  • Updated: Nov 8, 2023
  • CVE: CVE-2023-22341
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CWEs: