CVE-2020-5897: F5 BIG-IP Access Policy Manager

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

In versions 7.1.5-7.1.9, there is use-after-free memory vulnerability in the BIG-IP Edge Client Windows ActiveX component.

Affected products

  • F5 BIG-IP Access Policy Manager: from 11.6.1, up to and including 11.6.5.1; from 12.1.0, up to and including 12.1.5.1; from 13.1.0, up to and including 13.1.3.3; from 14.1.0, up to and including 14.1.2.5; from 15.0.0, up to and including 15.1.0.3
  • F5 BIG-IP Access Policy Manager Client: from 7.1.5, up to and including 7.1.9

Published 2020-05-12. Last modified 2026-06-17.