F5 has fixed a high-severity elevation of privilege vulnerability in BIG-IP.
The vulnerability (CVE-2024-45844) could allow an authenticated attacker with Manager role privileges or higher to elevate privileges and compromise the BIG-IP system.
The company released versions 17.1.1.4, 16.1.5, and 15.1.10.5 to address the issue.
F5 also addressed a medium-severity stored cross-site scripting (XSS) bug (CVE-2024-47139) in BIG-IQ.