CVE-2025-47148 Details
Description
When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with single logout (SLO) enabled on an access policy, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
A denial-of-service vulnerability has been identified in F5 BIG-IP systems configured as both SAML service providers and identity providers, with single logout enabled. Undisclosed requests in this configuration can lead to increased memory usage, causing system performance to degrade. This issue affects BIG-IP versions 15.1.0 through 15.1.10, 16.1.0 through 16.1.6, and 17.1.0 through 17.1.2, as well as BIG-IP APM, SSL Orchestrator, and related modules.
Users can upgrade to BIG-IP versions 15.1.10.8, 16.1.6.1, or 17.5.1 to address this vulnerability. For more information about managing BIG-IP product hotfixes, refer to the F5 article K13123.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 16, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://my.f5.com/manage/s/article/K000148816 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-404 | Improper Resource Shutdown or Release | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| f5 big-ip access policy manager | >= 15.1.0, < 15.1.10.8 >= 16.1.0, < 16.1.6.1 >= 17.1.0, < 17.1.3 17.5.0 |
CPE
Remediation
| |
| f5 big-ip ssl orchestrator | >= 15.1.0, < 15.1.10.8 >= 16.1.0, < 16.1.6.1 >= 17.1.0, < 17.1.3 17.5.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | Initial Analysis | [email protected] |
| Oct 15, 2025 | New CVE Received | [email protected] |