The management interface in F5 BIG-IP 9.4.3 allows remote authenticated users with Resource Manager privileges to inject arbitrary Perl code via unspecified configuration settings related to Perl EP3 with templates, probably triggering static code injection.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
http://osvdb.org/51116 | vdb entry |
http://www.securityfocus.com/bid/28639 | vdb entry |
http://www.securityfocus.com/archive/1/490496/100/0/threaded | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/49308 | vdb entry |