When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with single logout (SLO) enabled on an access policy, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
| Link | Resource |
|---|---|
| https://my.f5.com/manage/s/article/K000148816 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Oct 2025, 18:53
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://my.f5.com/manage/s/article/K000148816 - Vendor Advisory | |
| First Time |
F5
F5 big-ip Access Policy Manager F5 big-ip Ssl Orchestrator |
|
| CPE | cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_access_policy_manager:17.5.0:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_ssl_orchestrator:17.5.0:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_ssl_orchestrator:*:*:*:*:*:*:*:* |
15 Oct 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-15 14:15
Updated : 2025-10-21 18:53
NVD link : CVE-2025-47148
Mitre link : CVE-2025-47148
CVE.ORG link : CVE-2025-47148
JSON object : View
Products Affected
f5
- big-ip_ssl_orchestrator
- big-ip_access_policy_manager
CWE
CWE-404
Improper Resource Shutdown or Release
