CVE-2024-21789
HIGHDescription
When a BIG-IP ASM/Advanced WAF security policy is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Is your site exposed to CVE-2024-21789?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| f5 | big-ip_advanced_web_application_firewall |
| f5 | big-ip_application_security_manager |
References
Frequently Asked Questions
What is CVE-2024-21789? +
How severe is CVE-2024-21789? +
What products are affected by CVE-2024-21789? +
How do I check if I'm vulnerable to CVE-2024-21789? +
Related Vulnerabilities
Missing release of memory after effective lifetime, Missing release of resource after effective lifetime vulnerability in Apache Thrift THeaderTransport. This …
improper handling of exceptional conditions, Missing release of resource after effective lifetime vulnerability in Apache Thrift java bindings. This issue …
An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a race …
Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial …
thread-amount is a tool that gets the amount of threads in the current process. Prior to version 0.2.2, there are …
Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial …