CVE-2023-22418: F5 BIG-IP Access Policy Manager
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.7, 14.1.x before 14.1.5.3, and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy. This vulnerability allows an unauthenticated malicious attacker to build an open redirect URI. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected products
- F5 BIG-IP Access Policy Manager: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.3 (fixed in 14.1.5.3); from 15.1.0, before 15.1.7 (fixed in 15.1.7); from 16.1.0, before 16.1.3.3 (fixed in 16.1.3.3); from 17.0.0, before 17.0.0.2 (fixed in 17.0.0.2)
- F5 BIG-IP Advanced Firewall Manager: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.3 (fixed in 14.1.5.3); from 15.1.0, before 15.1.7 (fixed in 15.1.7); from 16.1.0, before 16.1.3.3 (fixed in 16.1.3.3); from 17.0.0, before 17.0.0.2 (fixed in 17.0.0.2)
- F5 BIG-IP Analytics: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.3 (fixed in 14.1.5.3); from 15.1.0, before 15.1.7 (fixed in 15.1.7); from 16.1.0, before 16.1.3.3 (fixed in 16.1.3.3); from 17.0.0, before 17.0.0.2 (fixed in 17.0.0.2)
- F5 BIG-IP Application Acceleration Manager: from 13.1.0, up to and including 13.1.5; from 15.1.0, before 15.1.7 (fixed in 15.1.7); from 16.1.0, before 16.1.3.3 (fixed in 16.1.3.3); from 17.0.0, before 17.0.0.2 (fixed in 17.0.0.2)
- F5 BIG-IP Application Security Manager: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.3 (fixed in 14.1.5.3); from 15.1.0, before 15.1.7 (fixed in 15.1.7); from 16.1.0, before 16.1.3.3 (fixed in 16.1.3.3); from 17.0.0, before 17.0.0.2 (fixed in 17.0.0.2)
- F5 BIG-IP Ddos Hybrid Defender: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.3 (fixed in 14.1.5.3); from 15.1.0, before 15.1.7 (fixed in 15.1.7); from 16.1.0, before 16.1.3.3 (fixed in 16.1.3.3)
- F5 BIG-IP Domain Name System: from 14.1.0, before 14.1.5.3 (fixed in 14.1.5.3); from 15.1.0, before 15.1.7 (fixed in 15.1.7); from 16.1.0, before 16.1.3.3 (fixed in 16.1.3.3); from 17.0.0, before 17.0.0.2 (fixed in 17.0.0.2)
- F5 BIG-IP Fraud Protection Service: from 13.1.0, up to and including 13.1.5; from 15.1.0, before 15.1.7 (fixed in 15.1.7); from 16.1.0, before 16.1.3.3 (fixed in 16.1.3.3); from 17.0.0, before 17.0.0.2 (fixed in 17.0.0.2)
- F5 BIG-IP Link Controller: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.3 (fixed in 14.1.5.3); from 15.1.0, before 15.1.7 (fixed in 15.1.7); from 16.1.0, before 16.1.3.3 (fixed in 16.1.3.3); from 17.0.0, before 17.0.0.2 (fixed in 17.0.0.2)
- F5 BIG-IP Local Traffic Manager: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.3 (fixed in 14.1.5.3); from 15.1.0, before 15.1.7 (fixed in 15.1.7); from 16.1.0, before 16.1.3.3 (fixed in 16.1.3.3); from 17.0.0, before 17.0.0.2 (fixed in 17.0.0.2)
- F5 BIG-IP Policy Enforcement Manager: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.3 (fixed in 14.1.5.3); from 15.1.0, before 15.1.7 (fixed in 15.1.7); from 16.1.0, before 16.1.3.3 (fixed in 16.1.3.3); from 17.0.0, before 17.0.0.2 (fixed in 17.0.0.2)
- F5 BIG-IP SSL Orchestrator: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.3 (fixed in 14.1.5.3); from 15.1.0, before 15.1.8.1 (fixed in 15.1.8.1); from 16.1.0, before 16.1.3.3 (fixed in 16.1.3.3); from 17.0.0, before 17.0.0.2 (fixed in 17.0.0.2)
Published 2023-02-01. Last modified 2026-06-17.