CVE-2020-5904: CSRF
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a cross-site request forgery (CSRF) vulnerability in the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, exists in an undisclosed page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5904?
CVE-2020-5904 has been assigned a medium severity rating due to its potential impact on system security.
How do I fix CVE-2020-5904?
To mitigate CVE-2020-5904, you should upgrade to a patched version of BIG-IP, specifically a version later than 15.1.0.3.
Which versions of BIG-IP are affected by CVE-2020-5904?
CVE-2020-5904 affects BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1.
What type of vulnerability is CVE-2020-5904?
CVE-2020-5904 is a cross-site request forgery (CSRF) vulnerability located in the Traffic Management User Interface (TMUI).
Is CVE-2020-5904 specific to a certain product from F5?
Yes, CVE-2020-5904 is specific to various F5 BIG-IP products, including Access Policy Manager and Local Traffic Manager.