CVE-2019-6653: XSS
Published Sep 25, 2019
·Updated
There is a Stored Cross Site Scripting vulnerability in the undisclosed page of a BIG-IQ 6.0.0-6.1.0 or 5.2.0-5.4.0 system. The attack can be stored by users granted the Device Manager and Administrator roles.
Affected Software
2 affected components
F5 BIG-IQ Centralized Management>=5.2.0<=5.4.0
F5 BIG-IQ Centralized Management>=6.0.0<=6.1.0
Event History
Sep 25, 2019
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-6653?
The severity of CVE-2019-6653 is medium with a severity value of 5.4.
2
How can the Stored Cross Site Scripting vulnerability in CVE-2019-6653 be exploited?
The Stored Cross Site Scripting vulnerability in CVE-2019-6653 can be exploited by users granted the Device Manager and Administrator roles.
3
What software versions are affected by CVE-2019-6653?
CVE-2019-6653 affects BIG-IQ Centralized Management versions between 5.2.0 and 5.4.0, as well as versions between 6.0.0 and 6.1.0.
4
How can I fix the Stored Cross Site Scripting vulnerability in CVE-2019-6653?
To fix the Stored Cross Site Scripting vulnerability in CVE-2019-6653, it is recommended to apply the necessary patches or updates provided by F5.