CVE-2023-28406: F5 BIG-IP Access Policy Manager

Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.

A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which may allow an authenticated attacker to read files with .xml extension. Access to restricted information is limited and the attacker does not control what information is obtained.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected products

  • F5 BIG-IP Access Policy Manager: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.4 (fixed in 14.1.5.4); from 15.1.0, before 15.1.8.2 (fixed in 15.1.8.2); from 16.1.0, before 16.1.3.4 (fixed in 16.1.3.4); from 17.0.0, before 17.1.0.1 (fixed in 17.1.0.1)
  • F5 BIG-IP Advanced Firewall Manager: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.4 (fixed in 14.1.5.4); from 15.1.0, before 15.1.8.2 (fixed in 15.1.8.2); from 16.1.0, before 16.1.3.4 (fixed in 16.1.3.4); from 17.0.0, before 17.1.0.1 (fixed in 17.1.0.1)
  • F5 BIG-IP Advanced Web Application Firewall: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.4 (fixed in 14.1.5.4); from 15.1.0, before 15.1.8.2 (fixed in 15.1.8.2); from 16.1.0, before 16.1.3.4 (fixed in 16.1.3.4); from 17.0.0, before 17.1.0.1 (fixed in 17.1.0.1)
  • F5 BIG-IP Analytics: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.4 (fixed in 14.1.5.4); from 15.1.0, before 15.1.8.2 (fixed in 15.1.8.2); from 16.1.0, before 16.1.3.4 (fixed in 16.1.3.4); from 17.0.0, before 17.1.0.1 (fixed in 17.1.0.1)
  • F5 BIG-IP Application Acceleration Manager: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.4 (fixed in 14.1.5.4); from 15.1.0, before 15.1.8.2 (fixed in 15.1.8.2); from 16.1.0, before 16.1.3.4 (fixed in 16.1.3.4); from 17.0.0, before 17.1.0.1 (fixed in 17.1.0.1)
  • F5 BIG-IP Application Security Manager: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.4 (fixed in 14.1.5.4); from 15.1.0, before 15.1.8.2 (fixed in 15.1.8.2); from 16.1.0, before 16.1.3.4 (fixed in 16.1.3.4); from 17.0.0, before 17.1.0.1 (fixed in 17.1.0.1)
  • F5 BIG-IP Application Visibility And Reporting: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.4 (fixed in 14.1.5.4); from 15.1.0, before 15.1.8.2 (fixed in 15.1.8.2); from 16.1.0, before 16.1.3.4 (fixed in 16.1.3.4); from 17.0.0, before 17.1.0.1 (fixed in 17.1.0.1)
  • F5 BIG-IP Carrier-Grade Nat: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.4 (fixed in 14.1.5.4); from 15.1.0, before 15.1.8.2 (fixed in 15.1.8.2); from 16.1.0, before 16.1.3.4 (fixed in 16.1.3.4); from 17.0.0, before 17.1.0.1 (fixed in 17.1.0.1)
  • F5 BIG-IP Ddos Hybrid Defender: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.4 (fixed in 14.1.5.4); from 15.1.0, before 15.1.8.2 (fixed in 15.1.8.2); from 16.1.0, before 16.1.3.4 (fixed in 16.1.3.4); from 17.0.0, before 17.1.0.1 (fixed in 17.1.0.1)
  • F5 BIG-IP Domain Name System: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.4 (fixed in 14.1.5.4); from 15.1.0, before 15.1.8.2 (fixed in 15.1.8.2); from 16.1.0, before 16.1.3.4 (fixed in 16.1.3.4); from 17.0.0, before 17.1.0.1 (fixed in 17.1.0.1)
  • F5 BIG-IP Edge Gateway: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.4 (fixed in 14.1.5.4); from 15.1.0, before 15.1.8.2 (fixed in 15.1.8.2); from 16.1.0, before 16.1.3.4 (fixed in 16.1.3.4); from 17.0.0, before 17.1.0.1 (fixed in 17.1.0.1)
  • F5 BIG-IP Fraud Protection Service: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.4 (fixed in 14.1.5.4); from 15.1.0, before 15.1.8.2 (fixed in 15.1.8.2); from 16.1.0, before 16.1.3.4 (fixed in 16.1.3.4); from 17.0.0, before 17.1.0.1 (fixed in 17.1.0.1)
  • F5 BIG-IP Global Traffic Manager: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.4 (fixed in 14.1.5.4); from 15.1.0, before 15.1.8.2 (fixed in 15.1.8.2); from 16.1.0, before 16.1.3.4 (fixed in 16.1.3.4); from 17.0.0, before 17.1.0.1 (fixed in 17.1.0.1)
  • F5 BIG-IP Link Controller: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.4 (fixed in 14.1.5.4); from 15.1.0, before 15.1.8.2 (fixed in 15.1.8.2); from 16.1.0, before 16.1.3.4 (fixed in 16.1.3.4); from 17.0.0, before 17.1.0.1 (fixed in 17.1.0.1)
  • F5 BIG-IP Local Traffic Manager: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.4 (fixed in 14.1.5.4); from 15.1.0, before 15.1.8.2 (fixed in 15.1.8.2); from 16.1.0, before 16.1.3.4 (fixed in 16.1.3.4); from 17.0.0, before 17.1.0.1 (fixed in 17.1.0.1)
  • F5 BIG-IP Policy Enforcement Manager: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.4 (fixed in 14.1.5.4); from 15.1.0, before 15.1.8.2 (fixed in 15.1.8.2); from 16.1.0, before 16.1.3.4 (fixed in 16.1.3.4); from 17.0.0, before 17.1.0.1 (fixed in 17.1.0.1)
  • F5 BIG-IP SSL Orchestrator: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.4 (fixed in 14.1.5.4); from 15.1.0, before 15.1.8.2 (fixed in 15.1.8.2); from 16.1.0, before 16.1.3.4 (fixed in 16.1.3.4); from 17.0.0, before 17.1.0.1 (fixed in 17.1.0.1)
  • F5 BIG-IP Webaccelerator: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.4 (fixed in 14.1.5.4); from 15.1.0, before 15.1.8.2 (fixed in 15.1.8.2); from 16.1.0, before 16.1.3.4 (fixed in 16.1.3.4); from 17.0.0, before 17.1.0.1 (fixed in 17.1.0.1)
  • F5 BIG-IP Websafe: from 13.1.0, up to and including 13.1.5; from 14.1.0, before 14.1.5.4 (fixed in 14.1.5.4); from 15.1.0, before 15.1.8.2 (fixed in 15.1.8.2); from 16.1.0, before 16.1.3.4 (fixed in 16.1.3.4); from 17.0.0, before 17.1.0.1 (fixed in 17.1.0.1)

Published 2023-05-03. Last modified 2026-06-17.