CVE-2019-6629: F5 BIG-IP Access Policy Manager
High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.
On BIG-IP 14.1.0-14.1.0.5, undisclosed SSL traffic to a virtual server configured with a Client SSL profile may cause TMM to fail and restart. The Client SSL profile must have session tickets enabled and use DHE cipher suites to be affected. This only impacts the data plane, there is no impact to the control plane.
Affected products
- F5 BIG-IP Access Policy Manager: from 14.1.0.1, up to and including 14.1.0.5
- F5 BIG-IP Advanced Firewall Manager: from 14.1.0.1, up to and including 14.1.0.5
- F5 BIG-IP Analytics: from 14.1.0.1, up to and including 14.1.0.5
- F5 BIG-IP Application Acceleration Manager: from 14.1.0.1, up to and including 14.1.0.5
- F5 BIG-IP Application Security Manager: from 14.1.0.1, up to and including 14.1.0.5
- F5 BIG-IP Domain Name System: from 14.1.0.1, up to and including 14.1.0.5
- F5 BIG-IP Edge Gateway: from 14.1.0.1, up to and including 14.1.0.5
- F5 BIG-IP Global Traffic Manager: from 14.1.0.1, up to and including 14.1.0.5
- F5 BIG-IP Link Controller: from 14.1.0.1, up to and including 14.1.0.5
- F5 BIG-IP Local Traffic Manager: from 14.1.0.1, up to and including 14.1.0.5
- F5 BIG-IP Policy Enforcement Manager: from 14.1.0.1, up to and including 14.1.0.5
- F5 BIG-IP Webaccelerator: from 14.1.0.1, up to and including 14.1.0.5
- F5 BIG-IP Websafe: from 14.1.0.1, up to and including 14.1.0.5
Published 2019-07-03. Last modified 2026-06-17.