First published: Tue Jan 14 2020(Updated: )
In BIG-IP APM portal access on versions 15.0.0-15.1.0, 14.0.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, when backend servers serve HTTP pages with special JavaScript code, this can lead to internal portal access name conflict.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Big-ip Access Policy Manager | >=11.5.2<=11.6.5 | |
F5 Big-ip Access Policy Manager | >=12.1.0<=12.1.5 | |
F5 Big-ip Access Policy Manager | >=13.1.0<=13.1.3 | |
F5 Big-ip Access Policy Manager | >=14.0.0<=14.1.2 | |
F5 Big-ip Access Policy Manager | >=15.0.0<=15.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5853 has a high severity rating due to potential access conflicts in the BIG-IP APM portal.
To fix CVE-2020-5853, upgrade the BIG-IP APM to the latest version recommended by F5.
CVE-2020-5853 affects BIG-IP APM versions 11.5.2 to 11.6.5.1, 12.1.0 to 12.1.5, 13.1.0 to 13.1.3.2, 14.0.0 to 14.1.2.3, and 15.0.0 to 15.1.0.
The risks associated with CVE-2020-5853 include unauthorized access and conflict in portal access due to improperly handled JavaScript.
F5 recommends applying the latest patches as the primary method to address CVE-2020-5853, as there are no documented workarounds.