CVE-2020-5905: XSS
Published Jul 1, 2020
·Updated
In version 11.6.1-11.6.5.2 of the BIG-IP system Configuration utility Network > WCCP page, the system does not sanitize all user-provided data before display.
Affected Software
11 affected components
F5 BIG-IP Access Policy Manager>=11.6.1<=11.6.5.2
F5 BIG-IP Advanced Firewall Manager>=11.6.1<=11.6.5.2
F5 BIG-IP Analytics>=11.6.1<=11.6.5.2
F5 Big-ip Application Acceleration Manager>=11.6.1<=11.6.5.2
F5 BIG-IP Application Security Manager>=11.6.1<=11.6.5.2
F5 Big-ip Domain Name System>=11.6.1<=11.6.5.2
F5 Big-ip Fraud Protection Service>=11.6.1<=11.6.5.2
F5 Big-ip Global Traffic Manager>=11.6.1<=11.6.5.2
F5 Big-ip Link Controller>=11.6.1<=11.6.5.2
F5 Big-ip Local Traffic Manager>=11.6.1<=11.6.5.2
F5 Big-ip Policy Enforcement Manager>=11.6.1<=11.6.5.2
Event History
Jul 1, 2020
CVE Published
via MITRE·02:40 PM
Data Sourced
via MITRE·02:40 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-5905?
CVE-2020-5905 has a severity rating of Medium.
2
How do I fix CVE-2020-5905?
To mitigate CVE-2020-5905, upgrade to the latest supported version of the F5 BIG-IP software.
3
What versions are affected by CVE-2020-5905?
CVE-2020-5905 affects F5 BIG-IP versions 11.6.1 to 11.6.5.2.
4
What is the impact of CVE-2020-5905?
The impact of CVE-2020-5905 can allow an attacker to perform Cross-Site Scripting (XSS) attacks.
5
Where can I find more information about CVE-2020-5905?
For more information on CVE-2020-5905, refer to F5's official security advisory.