CVE-2015-4040: F5 BIG-IP Access Policy Manager

Medium severity, CVSS 4.0. EPSS: 6.8% chance of exploitation in the next 30 days.

Directory traversal vulnerability in the configuration utility in F5 BIG-IP before 12.0.0 and Enterprise Manager 3.0.0 through 3.1.1 allows remote authenticated users to access arbitrary files in the web root via unspecified vectors.

Affected products

  • F5 BIG-IP Access Policy Manager: up to and including 11.6.0
  • F5 BIG-IP Advanced Firewall Manager: up to and including 11.6.0
  • F5 BIG-IP Analytics: up to and including 11.6.0
  • F5 BIG-IP Application Acceleration Manager: up to and including 11.6.0
  • F5 BIG-IP Application Security Manager: up to and including 11.6.0
  • F5 BIG-IP Edge Gateway: up to and including 11.3.0
  • F5 BIG-IP Global Traffic Manager: up to and including 11.3.0
  • F5 BIG-IP Link Controller: up to and including 11.3.0
  • F5 BIG-IP Local Traffic Manager: up to and including 11.6.0
  • F5 BIG-IP Policy Enforcement Manager: up to and including 11.3.0
  • F5 BIG-IP Protocol Security Module: up to and including 11.3.0
  • F5 BIG-IP WAN Optimization Manager: up to and including 11.3.0
  • F5 BIG-IP Webaccelerator: up to and including 11.3.0
  • F5 Enterprise Manager: version 3.0.0 only; version 3.1.0 only; version 3.1.1 only

Published 2015-09-17. Last modified 2026-06-17.