First published: Thu Jun 18 2009(Updated: )
Cross-site scripting (XSS) vulnerability in the login interface (my.logon.php3) in F5 FirePass SSL VPN 5.5 through 5.5.2 and 6.0 through 6.0.3 allows remote attackers to inject arbitrary web script or HTML via a base64-encoded xcho parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
F5 FirePass SSL VPN | =5.5.1 | |
F5 FirePass SSL VPN | =5.5.2 | |
F5 FirePass SSL VPN | =6.0.1 | |
F5 FirePass SSL VPN | =6.0.3 | |
F5 FirePass SSL VPN | =6.0 | |
F5 FirePass SSL VPN | =6.0.2 | |
F5 FirePass SSL VPN | =5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2119 has a moderate severity rating due to its potential for cross-site scripting attacks that can compromise user sessions.
To fix CVE-2009-2119, upgrade F5 FirePass SSL VPN to a version that patches this XSS vulnerability, specifically versions after 6.0.3.
CVE-2009-2119 affects users of F5 FirePass SSL VPN versions 5.5 to 6.0.3.
CVE-2009-2119 is a cross-site scripting (XSS) vulnerability allowing attackers to inject malicious scripts.
Yes, CVE-2009-2119 can be exploited remotely by attackers to inject arbitrary web scripts via the login interface.