CVE-2018-15332: F5 BIG-IP Access Policy Manager

High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.

The svpn component of the F5 BIG-IP APM client prior to version 7.1.7.2 for Linux and macOS runs as a privileged process and can allow an unprivileged user to get ownership of files owned by root on the local client host in a race condition.

Affected products

  • F5 BIG-IP Access Policy Manager: from 11.5.1, up to and including 11.6.3; from 12.1.0, up to and including 12.1.3; from 13.0.0, up to and including 13.1.1; version 14.0.0 only
  • F5 BIG-IP Access Policy Manager Client: from 7.1.5, up to and including 7.1.7

Published 2018-12-06. Last modified 2026-06-17.