CVE-2018-15335: F5 BIG-IP Access Policy Manager

Medium severity, CVSS 5.9. EPSS: 1.4% chance of exploitation in the next 30 days.

When APM 13.0.0-13.1.x is deployed as an OAuth Resource Server, APM becomes a client application to an external OAuth authorization server. In certain cases when communication between the BIG-IP APM and the OAuth authorization server is lost, APM may not display the intended message in the failure response

Affected products

  • F5 BIG-IP Access Policy Manager: from 13.0.0, up to and including 13.1.1

Published 2018-12-28. Last modified 2026-06-17.