|
196371
|
7.9 |
HIGH
Network
|
vmware
|
single_sign-on_for_tanzu
|
Single Sign-On for Vmware Tanzu all versions prior to 1.11.3 ,1.12.x versions prior to 1.12.4 and 1.13.x prior to 1.13.1 are vulnerable to user impersonation attack.If two users are logged in to the …
|
CWE-287
Improper Authentication
|
CVE-2020-5425
|
2024-11-21 14:34 |
2020-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196372
|
7.5 |
HIGH
Network
|
f5
|
big-ip_local_traffic_manager
|
On BIG-IP LTM 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.1, the Traffic Management Microkernel (TMM) process may consume excessive resources when processing SSL traffic and …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-5936
|
2024-11-21 14:34 |
2020-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196373
|
6.5 |
MEDIUM
Adjacent
|
f5
|
big-ip_access_policy_manager
|
On BIG-IP APM 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, and 13.1.0-13.1.3.3, when multiple HTTP requests from the same client to configured SAML Single Logout (SLO) URL are passing through a TCP Keep-Alive c…
|
NVD-CWE-noinfo
|
CVE-2020-5934
|
2024-11-21 14:34 |
2020-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196374
|
4.8 |
MEDIUM
Network
|
f5
|
big-ip_application_security_manager
|
On BIG-IP ASM 15.1.0-15.1.0.5, a cross-site scripting (XSS) vulnerability exists in the BIG-IP ASM Configuration utility response and blocking pages. An authenticated user with administrative privile…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5932
|
2024-11-21 14:34 |
2020-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196375
|
5.9 |
MEDIUM
Network
|
f5
|
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_access_policy_manager big-ip_analytics big-ip_application_security_manager<…
|
On BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, FPS, GTM, Link Controller, PEM) versions 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, and 13.1.0-13.1.3.3, when handling MQTT traffic through a BIG-IP virtual…
|
NVD-CWE-noinfo
|
CVE-2020-5935
|
2024-11-21 14:34 |
2020-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196376
|
7.5 |
HIGH
Network
|
f5
|
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_access_policy_manager big-ip_analytics big-ip_application_security_manager<…
|
On versions 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, when a BIG-IP system that has a virtual server configured with an HTTP compression profile process…
|
NVD-CWE-noinfo
|
CVE-2020-5933
|
2024-11-21 14:34 |
2020-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196377
|
7.5 |
HIGH
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system …
|
On BIG-IP 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, Virtual servers with a OneConnect profile may incorrectly handle WebSockets related HTTP response he…
|
NVD-CWE-noinfo
|
CVE-2020-5931
|
2024-11-21 14:34 |
2020-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196378
|
6.5 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system …
|
On BIG-IP 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, when negotiating IPSec tunnels with configured, authenticated peers, the peer may negotiate a different key length than the BIG-IP con…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-5938
|
2024-11-21 14:34 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196379
|
7.5 |
HIGH
Network
|
f5
|
big-ip_advanced_firewall_manager
|
On BIG-IP AFM 15.1.0-15.1.0.5, the Traffic Management Microkernel (TMM) may produce a core file while processing layer 4 (L4) behavioral denial-of-service (DoS) traffic.
|
NVD-CWE-noinfo
|
CVE-2020-5937
|
2024-11-21 14:34 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196380
|
5.5 |
MEDIUM
Local
|
checkpoint
|
zonealarm
|
Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to delete arbitrary files while restoring files in Anti-Ransomware.
|
NVD-CWE-noinfo
|
CVE-2020-6022
|
2024-11-21 14:34 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|