Trust & Security
The OAuth Profile Is the Door: F5 BIG-IP APM’s Heap Overflow Turns a Network Security Appliance Into an Unauthenticated Entry Point
A heap-based buffer overflow in F5 BIG-IP APM lets unauthenticated attackers execute code on the data plane when a virtual server pairs an access policy with an OAuth profile. CISA gave federal agencies three days to patch.
◆ Heath Callahan