← Back to feed
Vulnerabilities & PatchesEmerging1 sourceMay 11, 2022 · 17:00via API Security News

Issue 184: RCE in F5 BIG-IP suite, API security maturity, hardening GCP implementations

Brief

This week, we have news of a high severity remote code execution (RCE) vulnerability in the F5 BIG-IP security suite. We also feature an article from Curity on API security maturity, an article on hardening Google Cloud Platform implementations, and finally a threat matrix for GraphQL APIs.

Vulnerability: RCE vulnerability in F5’s BIG-IP security suite

This week, F5’s BIG-IP load balancing and security suite was affected by a Remote Code Execution (RCE) vulnerability . The vulnerability is in the iControl REST API that allowed remote access to platform configuration. Attackers could gain access to an exposed endpoint /mgmt/tm/util/bash that did not require any authentication.

The vulnerability was given a CVSS score of 9. 8 and is tracked as CVE-2022-1388. F5 have addressed the issue and advised users to patch their systems immediately.

Read more on API Security News