CVE-2018-5548: F5 BIG-IP Access Policy Manager
Medium severity, CVSS 6.1. EPSS: 1.4% chance of exploitation in the next 30 days.
On BIG-IP APM 11.6.0-11.6.3, an insecure AES ECB mode is used for orig_uri parameter in an undisclosed /vdesk link of APM virtual server configured with an access profile, allowing a malicious user to build a redirect URI value using different blocks of cipher texts.
Affected products
- F5 BIG-IP Access Policy Manager: from 11.6.1, up to and including 11.6.3
Published 2018-09-13. Last modified 2026-06-17.