First published: Tue Oct 01 2013(Updated: )
The access policy logon page (logon.inc) in F5 BIG-IP APM 11.1.0 through 11.2.1 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Access Policy Manager | =11.1.0 | |
F5 Access Policy Manager | =11.2.0 | |
F5 Access Policy Manager | =11.2.1 | |
F5 Access Policy Manager | =11.1.0 | |
F5 Access Policy Manager | =11.2.0 | |
F5 Access Policy Manager | =11.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5975 is considered a critical vulnerability due to its potential for clickjacking attacks.
To fix CVE-2013-5975, upgrade to F5 BIG-IP APM version 11.2.2 or later.
CVE-2013-5975 allows remote attackers to execute clickjacking attacks on users accessing the logon page.
CVE-2013-5975 affects F5 BIG-IP APM versions 11.1.0 through 11.2.1.
There are currently no known workarounds for mitigating CVE-2013-5975 other than upgrading the software.