CVE-2020-5934: F5 BIG-IP Access Policy Manager
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
On BIG-IP APM 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, and 13.1.0-13.1.3.3, when multiple HTTP requests from the same client to configured SAML Single Logout (SLO) URL are passing through a TCP Keep-Alive connection, traffic to TMM can be disrupted.
Affected products
- F5 BIG-IP Access Policy Manager: from 13.1.0, before 13.1.3.4 (fixed in 13.1.3.4); from 14.1.0, before 14.1.2.4 (fixed in 14.1.2.4); from 15.1.0, before 15.1.1 (fixed in 15.1.1)
Published 2020-10-29. Last modified 2026-06-17.