First published: Wed Sep 25 2019(Updated: )
There is a Stored Cross Site Scripting vulnerability in the undisclosed page of a BIG-IQ 6.0.0-6.1.0 or 5.2.0-5.4.0 system. The attack can be stored by users granted the Device Manager and Administrator roles.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP and BIG-IQ Centralized Management | >=5.2.0<=5.4.0 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=6.0.0<=6.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-6653 is medium with a severity value of 5.4.
The Stored Cross Site Scripting vulnerability in CVE-2019-6653 can be exploited by users granted the Device Manager and Administrator roles.
CVE-2019-6653 affects BIG-IQ Centralized Management versions between 5.2.0 and 5.4.0, as well as versions between 6.0.0 and 6.1.0.
To fix the Stored Cross Site Scripting vulnerability in CVE-2019-6653, it is recommended to apply the necessary patches or updates provided by F5.