CVE-2019-6599: XSS
In BIG-IP 11.6.1-11.6.3.2 or 11.5.1-11.5.8, or Enterprise Manager 3.1.1, improper escaping of values in an undisclosed page of the configuration utility may result with an improper handling on the JSON response when it is injected by a malicious script via a remote cross-site scripting (XSS) attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6599?
CVE-2019-6599 has a medium severity rating due to the potential for remote cross-site scripting (XSS) attacks.
How do I fix CVE-2019-6599?
To fix CVE-2019-6599, upgrade to the latest version of F5 BIG-IP Access Policy Manager that addresses this vulnerability.
What systems are affected by CVE-2019-6599?
CVE-2019-6599 affects F5 BIG-IP Access Policy Manager versions from 11.5.1 to 11.5.8 and 11.6.1 to 11.6.3.2.
What impact does CVE-2019-6599 have?
CVE-2019-6599 allows an attacker to inject malicious scripts through an insufficiently secured configuration utility.
Is CVE-2019-6599 a common vulnerability?
CVE-2019-6599 is a known vulnerability affecting specific versions of F5 software, but its prevalence depends on the usage of those versions in the field.