Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

CVE-2016-9256

CVE information

Published

6 years ago

Last Modified

6 years ago

CVSSv2.0 Severity

Medium

CVSSv3.1 Severity

High

Impact Analysis

Description

In F5 BIG-IP 12.1.0 through 12.1.2, permissions enforced by iControl can lag behind the actual permissions assigned to a user if the role_map is not reloaded between the time the permissions are changed and the time of the user's next request. This is a race condition that occurs rarely in normal usage; the typical period in which this is possible is limited to at most a few seconds after the permission change..

CVSSv2.0 Score

Severity
Medium
Base Score
6/10
Exploit Score
6.8/10
Access Vector
Network
Access Complexity
Medium
Authentication Required
Single
Impact Score
6.4/10
Confidentiality Impact
Partial
Availability Impact
Partial
Integrity Impact
Partial

CVSSv3.1 Score

Severity
High
Base Score
7.5/10
Exploit Score
1.6/10
Access Vector
Network
Access Complexity
High
Privileges Required
Low
Impact Score
5.9/10
Confidentiality Impact
High
Availability Impact
High
Integrity Impact
High
Scope
Unchanged
User Interaction
None

Products Affected

CPE Affected Vulnerable Excluding Edit
cpe:2.3:a:f5:big-ip_local_traffic_manager:12.1.2:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:f5:big-ip_local_traffic_manager:12.0.0:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:f5:big-ip_local_traffic_manager:12.1.0:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:f5:big-ip_local_traffic_manager:12.1.1:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:f5:big-ip_application_acceleration_manager:12.0.0:
  Yes
- -
cpe:2.3:a:f5:big-ip_application_acceleration_manager:12.1.0:
  Yes
- -
cpe:2.3:a:f5:big-ip_application_acceleration_manager:12.1.1:
  Yes
- -
cpe:2.3:a:f5:big-ip_application_acceleration_manager:12.1.2:
  Yes
- -
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:12.1.0:*:*:*:*
  Yes
- -
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:12.1.2:*:*:*:*
  Yes
- -
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:12.1.1:*:*:*:*
  Yes
- -
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:12.0.0:*:*:*:*
  Yes
- -
cpe:2.3:a:f5:big-ip_analytics:12.1.0:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:f5:big-ip_analytics:12.0.0:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:f5:big-ip_analytics:12.1.2:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:f5:big-ip_analytics:12.1.1:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:f5:big-ip_access_policy_manager:12.1.2:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:f5:big-ip_access_policy_manager:12.0.0:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:f5:big-ip_access_policy_manager:12.1.1:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:f5:big-ip_access_policy_manager:12.1.0:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:f5:big-ip_application_security_manager:12.1.1:*:*:
  Yes
- -
cpe:2.3:a:f5:big-ip_application_security_manager:12.1.0:*:*:
  Yes
- -
cpe:2.3:a:f5:big-ip_application_security_manager:12.0.0:*:*:
  Yes
- -
cpe:2.3:a:f5:big-ip_application_security_manager:12.1.2:*:*:
  Yes
- -
cpe:2.3:a:f5:big-ip_domain_name_system:12.1.2:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:f5:big-ip_domain_name_system:12.1.0:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:f5:big-ip_domain_name_system:12.0.0:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:f5:big-ip_domain_name_system:12.1.1:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:f5:big-ip_link_controller:12.1.1:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:f5:big-ip_link_controller:12.1.0:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:f5:big-ip_link_controller:12.1.2:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:f5:big-ip_link_controller:12.0.0:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:12.1.1:*:*:*:
  Yes
- -
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:12.1.2:*:*:*:
  Yes
- -
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:12.0.0:*:*:*:
  Yes
- -
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:12.1.0:*:*:*:
  Yes
- -
cpe:2.3:a:f5:big-ip_websafe:12.1.0:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:f5:big-ip_websafe:12.0.0:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:f5:big-ip_websafe:12.1.1:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:f5:big-ip_websafe:12.1.2:*:*:*:*:*:*:*
  Yes
- -