important · Edge devices
Public analysis now makes BIG-IP APM's exploited OAuth overflow reproducible as unauthenticated code execution.
Affects
F5 BIG-IP Access Policy Manager, an edge access and authentication appliance, when an OAuth profile is attached to a virtual server.
On a virtual server with both an access policy and OAuth Authorization Server profile, an oversized Authorization header can corrupt a callback pointer. Heap shaping and a ROP chain append a command to the TMM finish script, which executes when TMM crashes.
Detail and 4 sources
A fix is published, but pre-fix images remain accepted.
Sources