A heap overflow in BIG-IP APM hands unauthenticated attackers code execution on any appliance serving as an OAuth authorization server.