First published: Fri Jun 09 2017(Updated: )
A stored cross-site scripting (XSS) vulnerability in the Configuration utility device name change page in BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, PSM, WebAccelerator, WOM and WebSafe version 12.0.0 - 12.1.2, 11.4.0 - 11.6.1, and 11.2.1 allows an authenticated user to inject arbitrary web script or HTML. Exploitation requires Resource Administrator or Administrator privileges, and it could cause the Configuration utility client to become unstable.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Big-ip Local Traffic Manager | =11.2.1 | |
F5 Big-ip Local Traffic Manager | =11.4.0 | |
F5 Big-ip Local Traffic Manager | =11.4.1 | |
F5 Big-ip Local Traffic Manager | =11.5.0 | |
F5 Big-ip Local Traffic Manager | =11.5.1 | |
F5 Big-ip Local Traffic Manager | =11.5.2 | |
F5 Big-ip Local Traffic Manager | =11.5.3 | |
F5 Big-ip Local Traffic Manager | =11.5.4 | |
F5 Big-ip Local Traffic Manager | =11.6.0 | |
F5 Big-ip Local Traffic Manager | =11.6.1 | |
F5 Big-ip Local Traffic Manager | =12.0.0 | |
F5 Big-ip Local Traffic Manager | =12.1.0 | |
F5 Big-ip Local Traffic Manager | =12.1.1 | |
F5 Big-ip Local Traffic Manager | =12.1.2 | |
F5 Big-ip Application Acceleration Manager | =11.4.0 | |
F5 Big-ip Application Acceleration Manager | =11.4.1 | |
F5 Big-ip Application Acceleration Manager | =11.5.0 | |
F5 Big-ip Application Acceleration Manager | =11.5.1 | |
F5 Big-ip Application Acceleration Manager | =11.5.2 | |
F5 Big-ip Application Acceleration Manager | =11.5.3 | |
F5 Big-ip Application Acceleration Manager | =11.5.4 | |
F5 Big-ip Application Acceleration Manager | =11.6.0 | |
F5 Big-ip Application Acceleration Manager | =11.6.1 | |
F5 Big-ip Application Acceleration Manager | =12.0.0 | |
F5 Big-ip Application Acceleration Manager | =12.1.0 | |
F5 Big-ip Application Acceleration Manager | =12.1.1 | |
F5 Big-ip Application Acceleration Manager | =12.1.2 | |
F5 BIG-IP Advanced Firewall Manager | =11.2.1 | |
F5 BIG-IP Advanced Firewall Manager | =11.4.0 | |
F5 BIG-IP Advanced Firewall Manager | =11.4.1 | |
F5 BIG-IP Advanced Firewall Manager | =11.5.0 | |
F5 BIG-IP Advanced Firewall Manager | =11.5.1 | |
F5 BIG-IP Advanced Firewall Manager | =11.5.2 | |
F5 BIG-IP Advanced Firewall Manager | =11.5.3 | |
F5 BIG-IP Advanced Firewall Manager | =11.5.4 | |
F5 BIG-IP Advanced Firewall Manager | =11.6.0 | |
F5 BIG-IP Advanced Firewall Manager | =11.6.1 | |
F5 BIG-IP Advanced Firewall Manager | =12.0.0 | |
F5 BIG-IP Advanced Firewall Manager | =12.1.0 | |
F5 BIG-IP Advanced Firewall Manager | =12.1.1 | |
F5 BIG-IP Advanced Firewall Manager | =12.1.2 | |
F5 BIG-IP Analytics | =11.2.1 | |
F5 BIG-IP Analytics | =11.4.0 | |
F5 BIG-IP Analytics | =11.4.1 | |
F5 BIG-IP Analytics | =11.5.0 | |
F5 BIG-IP Analytics | =11.5.1 | |
F5 BIG-IP Analytics | =11.5.2 | |
F5 BIG-IP Analytics | =11.5.3 | |
F5 BIG-IP Analytics | =11.5.4 | |
F5 BIG-IP Analytics | =11.6.0 | |
F5 BIG-IP Analytics | =11.6.1 | |
F5 BIG-IP Analytics | =12.0.0 | |
F5 BIG-IP Analytics | =12.1.0 | |
F5 BIG-IP Analytics | =12.1.1 | |
F5 BIG-IP Analytics | =12.1.2 | |
F5 BIG-IP Access Policy Manager | =11.2.1 | |
F5 BIG-IP Access Policy Manager | =11.4.0 | |
F5 BIG-IP Access Policy Manager | =11.4.1 | |
F5 BIG-IP Access Policy Manager | =11.5.0 | |
F5 BIG-IP Access Policy Manager | =11.5.1 | |
F5 BIG-IP Access Policy Manager | =11.5.2 | |
F5 BIG-IP Access Policy Manager | =11.5.3 | |
F5 BIG-IP Access Policy Manager | =11.5.4 | |
F5 BIG-IP Access Policy Manager | =11.6.0 | |
F5 BIG-IP Access Policy Manager | =11.6.1 | |
F5 BIG-IP Access Policy Manager | =12.0.0 | |
F5 BIG-IP Access Policy Manager | =12.1.0 | |
F5 BIG-IP Access Policy Manager | =12.1.1 | |
F5 BIG-IP Access Policy Manager | =12.1.2 | |
F5 BIG-IP Application Security Manager | =11.2.1 | |
F5 BIG-IP Application Security Manager | =11.4.0 | |
F5 BIG-IP Application Security Manager | =11.4.1 | |
F5 BIG-IP Application Security Manager | =11.5.0 | |
F5 BIG-IP Application Security Manager | =11.5.1 | |
F5 BIG-IP Application Security Manager | =11.5.2 | |
F5 BIG-IP Application Security Manager | =11.5.3 | |
F5 BIG-IP Application Security Manager | =11.5.4 | |
F5 BIG-IP Application Security Manager | =11.6.0 | |
F5 BIG-IP Application Security Manager | =11.6.1 | |
F5 BIG-IP Application Security Manager | =12.0.0 | |
F5 BIG-IP Application Security Manager | =12.1.0 | |
F5 BIG-IP Application Security Manager | =12.1.1 | |
F5 BIG-IP Application Security Manager | =12.1.2 | |
F5 Big-ip Domain Name System | =12.0.0 | |
F5 Big-ip Domain Name System | =12.1.0 | |
F5 Big-ip Domain Name System | =12.1.1 | |
F5 Big-ip Domain Name System | =12.1.2 | |
F5 Big-ip Edge Gateway | =11.2.1 | |
F5 Big-ip Global Traffic Manager | =11.2.1 | |
F5 Big-ip Global Traffic Manager | =11.4.0 | |
F5 Big-ip Global Traffic Manager | =11.4.1 | |
F5 Big-ip Global Traffic Manager | =11.5.0 | |
F5 Big-ip Global Traffic Manager | =11.5.1 | |
F5 Big-ip Global Traffic Manager | =11.5.2 | |
F5 Big-ip Global Traffic Manager | =11.5.3 | |
F5 Big-ip Global Traffic Manager | =11.5.4 | |
F5 Big-ip Global Traffic Manager | =11.6.0 | |
F5 Big-ip Global Traffic Manager | =11.6.1 | |
F5 Big-ip Link Controller | =11.2.1 | |
F5 Big-ip Link Controller | =11.4.0 | |
F5 Big-ip Link Controller | =11.4.1 | |
F5 Big-ip Link Controller | =11.5.0 | |
F5 Big-ip Link Controller | =11.5.1 | |
F5 Big-ip Link Controller | =11.5.2 | |
F5 Big-ip Link Controller | =11.5.3 | |
F5 Big-ip Link Controller | =11.5.4 | |
F5 Big-ip Link Controller | =11.6.0 | |
F5 Big-ip Link Controller | =11.6.1 | |
F5 Big-ip Link Controller | =12.0.0 | |
F5 Big-ip Link Controller | =12.1.0 | |
F5 Big-ip Link Controller | =12.1.1 | |
F5 Big-ip Link Controller | =12.1.2 | |
F5 Big-ip Policy Enforcement Manager | =11.4.0 | |
F5 Big-ip Policy Enforcement Manager | =11.4.1 | |
F5 Big-ip Policy Enforcement Manager | =11.5.0 | |
F5 Big-ip Policy Enforcement Manager | =11.5.1 | |
F5 Big-ip Policy Enforcement Manager | =11.5.2 | |
F5 Big-ip Policy Enforcement Manager | =11.5.3 | |
F5 Big-ip Policy Enforcement Manager | =11.5.4 | |
F5 Big-ip Policy Enforcement Manager | =11.6.0 | |
F5 Big-ip Policy Enforcement Manager | =11.6.1 | |
F5 Big-ip Policy Enforcement Manager | =12.0.0 | |
F5 Big-ip Policy Enforcement Manager | =12.1.0 | |
F5 Big-ip Policy Enforcement Manager | =12.1.1 | |
F5 Big-ip Policy Enforcement Manager | =12.1.2 | |
F5 Big-ip Protocol Security Module | =11.4.0 | |
F5 Big-ip Protocol Security Module | =11.4.1 | |
F5 Big-ip Webaccelerator | =11.2.1 | |
F5 Big-ip Websafe | =11.6.0 | |
F5 Big-ip Websafe | =11.6.1 | |
F5 Big-ip Websafe | =12.0.0 | |
F5 Big-ip Websafe | =12.1.0 | |
F5 Big-ip Websafe | =12.1.1 | |
F5 Big-ip Websafe | =12.1.2 | |
F5 Big-ip Wan Optimization Manager | =11.2.1 | |
F5 Enterprise Manager | =3.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.