CVE-2020-5889: XSS
On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, in BIG-IP APM portal access, a specially crafted HTTP request can lead to reflected XSS after the BIG-IP APM system rewrites the HTTP response from the untrusted backend server and sends it to the client.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5889?
CVE-2020-5889 is classified as a high severity vulnerability due to the potential for reflected XSS attacks.
How do I fix CVE-2020-5889?
To mitigate CVE-2020-5889, upgrade the F5 BIG-IP Access Policy Manager to a version that is not affected.
What versions are affected by CVE-2020-5889?
CVE-2020-5889 affects BIG-IP APM portal access on versions 14.1.0 to 14.1.2.3, 15.0.0 to 15.0.1.2, and 15.1.0 to 15.1.0.1.
What type of attack can be executed due to CVE-2020-5889?
CVE-2020-5889 allows an attacker to exploit reflected cross-site scripting (XSS) vulnerabilities.
How does CVE-2020-5889 occur?
CVE-2020-5889 occurs when a specially crafted HTTP request leads to improper handling of HTTP responses from untrusted backend servers.