First published: Tue Oct 28 2014(Updated: )
Cross-site scripting (XSS) vulnerability in tmui/dashboard/echo.jsp in the Configuration utility in F5 BIG-IP LTM, APM, ASM, GTM, and Link Controller 11.0.0 before 11.6.0 and 10.1.0 through 10.2.4, AAM 11.4.0 before 11.6.0, AFM and PEM 11.3.0 before 11.6.0, Analytics 11.0.0 through 11.5.1, Edge Gateway, WebAccelerator, and WOM 11.0.0 through 11.3.0 and 10.1.0 through 10.2.4, and PSM 11.0.0 through 11.4.1 and 10.1.0 through 10.2.4 and Enterprise Manager 3.0.0 through 3.1.1 and 2.1.0 through 2.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP Advanced Firewall Manager | =11.3.0 | |
F5 BIG-IP Advanced Firewall Manager | =11.4.0 | |
F5 BIG-IP Advanced Firewall Manager | =11.4.1 | |
F5 BIG-IP Advanced Firewall Manager | =11.5.0 | |
F5 BIG-IP Advanced Firewall Manager | =11.5.1 | |
F5 BIG-IP Policy Enforcement Manager | =11.3.0 | |
F5 BIG-IP Policy Enforcement Manager | =11.4.0 | |
F5 BIG-IP Policy Enforcement Manager | =11.4.1 | |
F5 BIG-IP Policy Enforcement Manager | =11.5.0 | |
F5 BIG-IP Policy Enforcement Manager | =11.5.1 | |
F5 Application Security Manager | =10.1.0 | |
F5 Application Security Manager | =10.2.0 | |
F5 Application Security Manager | =10.2.1 | |
F5 Application Security Manager | =10.2.2 | |
F5 Application Security Manager | =10.2.3 | |
F5 Application Security Manager | =10.2.4 | |
F5 Application Security Manager | =11.0.0 | |
F5 Application Security Manager | =11.1.0 | |
F5 Application Security Manager | =11.2.0 | |
F5 Application Security Manager | =11.2.1 | |
F5 Application Security Manager | =11.3.0 | |
F5 Application Security Manager | =11.4.0 | |
F5 Application Security Manager | =11.4.1 | |
F5 Application Security Manager | =11.5.0 | |
F5 Application Security Manager | =11.5.1 | |
F5 BIG-IP Application Acceleration Manager | =11.4.0 | |
F5 BIG-IP Application Acceleration Manager | =11.4.1 | |
F5 BIG-IP Application Acceleration Manager | =11.5.0 | |
F5 BIG-IP Application Acceleration Manager | =11.5.1 | |
F5 Enterprise Manager | =3.0.0 | |
F5 Enterprise Manager | =3.1.0 | |
F5 Enterprise Manager | =3.1.1 | |
F5 Enterprise Manager | =2.1.0 | |
F5 Enterprise Manager | =2.2.0 | |
F5 Enterprise Manager | =2.3.0 | |
F5 BIG-IP Edge Gateway | =10.1.0 | |
F5 BIG-IP Edge Gateway | =10.2.0 | |
F5 BIG-IP Edge Gateway | =10.2.1 | |
F5 BIG-IP Edge Gateway | =10.2.2 | |
F5 BIG-IP Edge Gateway | =10.2.3 | |
F5 BIG-IP Edge Gateway | =10.2.4 | |
F5 BIG-IP Edge Gateway | =11.0.0 | |
F5 BIG-IP Edge Gateway | =11.1.0 | |
F5 BIG-IP Edge Gateway | =11.2.0 | |
F5 BIG-IP Edge Gateway | =11.2.1 | |
F5 BIG-IP Edge Gateway | =11.3.0 | |
Riverbed SteelApp Traffic Manager | =10.1.0 | |
Riverbed SteelApp Traffic Manager | =10.2.0 | |
Riverbed SteelApp Traffic Manager | =10.2.1 | |
Riverbed SteelApp Traffic Manager | =10.2.2 | |
Riverbed SteelApp Traffic Manager | =10.2.3 | |
Riverbed SteelApp Traffic Manager | =10.2.4 | |
Riverbed SteelApp Traffic Manager | =11.0.0 | |
Riverbed SteelApp Traffic Manager | =11.1.0 | |
Riverbed SteelApp Traffic Manager | =11.2.0 | |
Riverbed SteelApp Traffic Manager | =11.2.1 | |
Riverbed SteelApp Traffic Manager | =11.3.0 | |
Riverbed SteelApp Traffic Manager | =11.4.0 | |
Riverbed SteelApp Traffic Manager | =11.4.1 | |
Riverbed SteelApp Traffic Manager | =11.5.0 | |
Riverbed SteelApp Traffic Manager | =11.5.1 | |
F5 BIG-IP Link Controller | =10.1.0 | |
F5 BIG-IP Link Controller | =10.2.0 | |
F5 BIG-IP Link Controller | =10.2.1 | |
F5 BIG-IP Link Controller | =10.2.2 | |
F5 BIG-IP Link Controller | =10.2.3 | |
F5 BIG-IP Link Controller | =10.2.4 | |
F5 BIG-IP Link Controller | =11.0.0 | |
F5 BIG-IP Link Controller | =11.1.0 | |
F5 BIG-IP Link Controller | =11.2.0 | |
F5 BIG-IP Link Controller | =11.2.1 | |
F5 BIG-IP Link Controller | =11.3.0 | |
F5 BIG-IP Link Controller | =11.4.0 | |
F5 BIG-IP Link Controller | =11.4.1 | |
F5 BIG-IP Link Controller | =11.5.0 | |
F5 BIG-IP Link Controller | =11.5.1 | |
Riverbed SteelApp Traffic Manager | =10.1.0 | |
Riverbed SteelApp Traffic Manager | =10.2.0 | |
Riverbed SteelApp Traffic Manager | =10.2.1 | |
Riverbed SteelApp Traffic Manager | =10.2.2 | |
Riverbed SteelApp Traffic Manager | =10.2.3 | |
Riverbed SteelApp Traffic Manager | =10.2.4 | |
Riverbed SteelApp Traffic Manager | =11.0.0 | |
Riverbed SteelApp Traffic Manager | =11.1.0 | |
Riverbed SteelApp Traffic Manager | =11.2.0 | |
Riverbed SteelApp Traffic Manager | =11.2.1 | |
Riverbed SteelApp Traffic Manager | =11.3.0 | |
Riverbed SteelApp Traffic Manager | =11.4.0 | |
Riverbed SteelApp Traffic Manager | =11.4.1 | |
Riverbed SteelApp Traffic Manager | =11.5.0 | |
Riverbed SteelApp Traffic Manager | =11.5.1 | |
F5 Access Policy Manager | =10.1.0 | |
F5 Access Policy Manager | =10.2.0 | |
F5 Access Policy Manager | =10.2.1 | |
F5 Access Policy Manager | =10.2.2 | |
F5 Access Policy Manager | =10.2.3 | |
F5 Access Policy Manager | =10.2.4 | |
F5 Access Policy Manager | =11.0.0 | |
F5 Access Policy Manager | =11.1.0 | |
F5 Access Policy Manager | =11.2.0 | |
F5 Access Policy Manager | =11.2.1 | |
F5 Access Policy Manager | =11.3.0 | |
F5 Access Policy Manager | =11.4.0 | |
F5 Access Policy Manager | =11.4.1 | |
F5 Access Policy Manager | =11.5.0 | |
F5 Access Policy Manager | =11.5.1 | |
F5 BIG-IP Protocol Security Manager | =10.1.0 | |
F5 BIG-IP Protocol Security Manager | =10.2.0 | |
F5 BIG-IP Protocol Security Manager | =10.2.1 | |
F5 BIG-IP Protocol Security Manager | =10.2.2 | |
F5 BIG-IP Protocol Security Manager | =10.2.3 | |
F5 BIG-IP Protocol Security Manager | =10.2.4 | |
F5 BIG-IP Protocol Security Manager | =11.0.0 | |
F5 BIG-IP Protocol Security Manager | =11.1.0 | |
F5 BIG-IP Protocol Security Manager | =11.2.0 | |
F5 BIG-IP Protocol Security Manager | =11.2.1 | |
F5 BIG-IP Protocol Security Manager | =11.3.0 | |
F5 BIG-IP Protocol Security Manager | =11.4.0 | |
F5 BIG-IP Protocol Security Manager | =11.4.1 | |
F5 BIG-IP WebAccelerator | =10.1.0 | |
F5 BIG-IP WebAccelerator | =10.2.0 | |
F5 BIG-IP WebAccelerator | =10.2.1 | |
F5 BIG-IP WebAccelerator | =10.2.2 | |
F5 BIG-IP WebAccelerator | =10.2.3 | |
F5 BIG-IP WebAccelerator | =10.2.4 | |
F5 BIG-IP WebAccelerator | =11.0.0 | |
F5 BIG-IP WebAccelerator | =11.1.0 | |
F5 BIG-IP WebAccelerator | =11.2.0 | |
F5 BIG-IP WebAccelerator | =11.2.1 | |
F5 BIG-IP WebAccelerator | =11.3.0 | |
Exinda WAN Optimization Suite | =10.1.0 | |
Exinda WAN Optimization Suite | =10.2.0 | |
Exinda WAN Optimization Suite | =10.2.1 | |
Exinda WAN Optimization Suite | =10.2.2 | |
Exinda WAN Optimization Suite | =10.2.3 | |
Exinda WAN Optimization Suite | =10.2.4 | |
Exinda WAN Optimization Suite | =11.0.0 | |
Exinda WAN Optimization Suite | =11.1.0 | |
Exinda WAN Optimization Suite | =11.2.0 | |
Exinda WAN Optimization Suite | =11.2.1 | |
Exinda WAN Optimization Suite | =11.3.0 | |
F5 BIG-IP Analytics | =11.0.0 | |
F5 BIG-IP Analytics | =11.1.0 | |
F5 BIG-IP Analytics | =11.2.0 | |
F5 BIG-IP Analytics | =11.2.1 | |
F5 BIG-IP Analytics | =11.3.0 | |
F5 BIG-IP Analytics | =11.4.0 | |
F5 BIG-IP Analytics | =11.4.1 | |
F5 BIG-IP Analytics | =11.5.0 | |
F5 BIG-IP Analytics | =11.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4023 has a severity rating that varies depending on the specific context and implementation of the affected software.
To mitigate CVE-2014-4023, upgrade to the fixed versions provided by F5 in their security advisory.
CVE-2014-4023 can allow an attacker to execute arbitrary JavaScript in the context of an affected user's session, compromising user data.
CVE-2014-4023 affects F5 BIG-IP versions including 10.1.0 to 10.2.4 and 11.0.0 to 11.5.1.
CVE-2014-4023 was identified through security assessments focusing on cross-site scripting vulnerabilities within F5 BIG-IP management interfaces.