CVE-2019-6641: F5 BIG-IP Access Policy Manager

Medium severity, CVSS 6.5. EPSS: 2% chance of exploitation in the next 30 days.

On BIG-IP 12.1.0-12.1.4.1, undisclosed requests can cause iControl REST processes to crash. The attack can only come from an authenticated user; all roles are capable of performing the attack. Unauthenticated users cannot perform this attack.

Affected products

  • F5 BIG-IP Access Policy Manager: from 12.1.2, up to and including 12.1.4
  • F5 BIG-IP Advanced Firewall Manager: from 12.1.2, up to and including 12.1.4
  • F5 BIG-IP Analytics: from 12.1.2, up to and including 12.1.4
  • F5 BIG-IP Application Acceleration Manager: from 12.1.2, up to and including 12.1.4
  • F5 BIG-IP Application Security Manager: from 12.1.2, up to and including 12.1.4
  • F5 BIG-IP Domain Name System: from 12.1.2, up to and including 12.1.4
  • F5 BIG-IP Edge Gateway: from 12.1.2, up to and including 12.1.4
  • F5 BIG-IP Fraud Protection Service: from 12.1.2, up to and including 12.1.4
  • F5 BIG-IP Global Traffic Manager: from 12.1.2, up to and including 12.1.4
  • F5 BIG-IP Link Controller: from 12.1.2, up to and including 12.1.4
  • F5 BIG-IP Local Traffic Manager: from 12.1.2, up to and including 12.1.4
  • F5 BIG-IP Policy Enforcement Manager: from 12.1.2, up to and including 12.1.4
  • F5 BIG-IP Webaccelerator: from 12.1.2, up to and including 12.1.4

Published 2019-07-03. Last modified 2026-06-17.