Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HF5 Big Ip Access Policy Manager
APPF515.1.0 – 15.1.0.2 (excl.)12.1.0 – 12.1.5.2 (excl.)13.1.0 – 13.1.3.4 (excl.)14.1.0 – 14.1.2.5 (excl.)15.0.0 – 15.0.1.4 (excl.)F5 Big Ip Advanced Firewall Manager
APPF512.1.0 – 12.1.5.2 (excl.)15.1.0 – 15.1.0.2 (excl.)15.0.0 – 15.0.1.4 (excl.)14.1.0 – 14.1.2.5 (excl.)13.1.0 – 13.1.3.4 (excl.)F5 Big Ip Analytics
APPF515.0.0 – 15.0.1.3 (excl.)12.1.0 – 12.1.513.1.0 – 13.1.314.1.0 – 14.1.215.1.0 – 15.1.0.2 (excl.)F5 Big Ip Application Acceleration Manager
APPF512.1.0 – 12.1.5.2 (excl.)15.1.0 – 15.1.0.2 (excl.)13.1.0 – 13.1.3.4 (excl.)14.1.0 – 14.1.2.5 (excl.)15.0.0 – 15.0.1.4 (excl.)F5 Big Ip Application Security Manager
APPF514.1.0 – 14.1.2.5 (excl.)15.1.0 – 15.1.0.2 (excl.)12.1.0 – 12.1.5.2 (excl.)13.1.0 – 13.1.3.4 (excl.)15.0.0 – 15.0.1.4 (excl.)F5 Big Ip Application Visibility And Reporting
APPF515.1.0 – 15.1.1 (excl.)12.1.0 – 12.1.5.2 (excl.)13.1.0 – 13.1.314.1.0 – 14.1.2.5 (excl.)F5 Big Ip Domain Name System
APPF515.1.0 – 15.1.0.2 (excl.)12.1.0 – 12.1.5.2 (excl.)13.1.0 – 13.1.3.4 (excl.)14.1.0 – 14.1.2.5 (excl.)15.0.0 – 15.0.1.4 (excl.)F5 Big Ip Edge Gateway
APPF515.1.0 – 15.1.0.2 (excl.)12.1.0 – 12.1.5.2 (excl.)13.1.0 – 13.1.3.4 (excl.)14.1.0 – 14.1.2.5 (excl.)15.0.0 – 15.0.1.4 (excl.)F5 Big Ip Fraud Protection Service
APPF512.1.0 – 12.1.5.2 (excl.)15.1.0 – 15.1.0.2 (excl.)15.0.0 – 15.0.1.4 (excl.)14.1.0 – 14.1.2.5 (excl.)13.1.0 – 13.1.3.4 (excl.)F5 Big Ip Global Traffic Manager
APPF515.0.0 – 15.0.1.4 (excl.)12.1.0 – 12.1.5.2 (excl.)13.1.0 – 13.1.3.4 (excl.)14.1.0 – 14.1.2.5 (excl.)15.1.0 – 15.1.0.2 (excl.)F5 Big Ip Link Controller
APPF515.1.0 – 15.1.0.2 (excl.)12.1.0 – 12.1.5.2 (excl.)13.1.0 – 13.1.3.4 (excl.)14.1.0 – 14.1.2.5 (excl.)15.0.0 – 15.0.1.4 (excl.)F5 Big Ip Local Traffic Manager
APPF515.0.0 – 15.0.1.4 (excl.)12.1.0 – 12.1.5.2 (excl.)13.1.0 – 13.1.3.4 (excl.)14.1.0 – 14.1.2.5 (excl.)15.1.0 – 15.1.0.2 (excl.)F5 Big Ip Policy Enforcement Manager
APPF515.1.0 – 15.1.0.2 (excl.)12.1.0 – 12.1.5.2 (excl.)13.1.0 – 13.1.3.4 (excl.)14.1.0 – 14.1.2.5 (excl.)15.0.0 – 15.0.1.4 (excl.)F5 Big Ip Webaccelerator
APPF515.0.0 – 15.0.1.4 (excl.)12.1.0 – 12.1.5.2 (excl.)13.1.0 – 13.1.3.4 (excl.)14.1.0 – 14.1.2.5 (excl.)15.1.0 – 15.1.0.2 (excl.)F5 Big Iq Centralized Management
APPF55.4.07.0.06.0.0 – 6.1.0F5 Iworkflow
APPF52.3.0Lodash
APPLodash< 4.17.12Netapp Active Iq Unified Manager
APPNetappall versionsNetapp Service Level Manager
APPNetappall versionsOracle Banking Extensibility Workbench
APPOracle14.3.014.4.0Red Hat Virtualization Manager
APPRedhat4.3
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References
Related vulnerabilities
CVE-2025-53521CRITICAL9.3⚠ KEVPL ✓same product
RCE w F5 BIG-IP APM poprzez złośliwy ruch sieciowy (stack buffer overflow)
CVE-2023-46747CRITICAL9.8⚠ KEVPL ✓same product
F5 BIG-IP: Obejście uwierzytelnienia i zdalne wykonanie poleceń (RCE)
CVE-2022-1388CRITICAL9.8⚠ KEVPL ✓same product
F5 BIG-IP: Pominięcie uwierzytelnienia iControl REST (RCE)
CVE-2021-44228CRITICAL10.0⚠ KEVPL ✓same product
Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup
CVE-2021-22986CRITICAL9.8⚠ KEVPL ✓same product
F5 BIG-IP/BIG-IQ iControl REST — nieuwierzytelniony RCE