CVE-2020-5927: XSS
In versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, and 14.1.0-14.1.2.6, BIG-IP ASM Configuration utility Stored-Cross Site Scripting.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5927?
CVE-2020-5927 is rated as high severity due to the risk of stored cross-site scripting in affected versions of BIG-IP ASM Configuration utility.
How do I fix CVE-2020-5927?
To fix CVE-2020-5927, upgrade your F5 BIG-IP Application Security Manager to a version that is not vulnerable, such as 14.1.2.7 or later, 15.0.1.4 or later, or 15.1.0.5 or later.
Which versions of F5 BIG-IP Application Security Manager are affected by CVE-2020-5927?
CVE-2020-5927 affects F5 BIG-IP Application Security Manager versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, and 14.1.0-14.1.2.6.
What type of vulnerability is CVE-2020-5927?
CVE-2020-5927 is a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into the application.
Can CVE-2020-5927 be exploited remotely?
Yes, CVE-2020-5927 can be exploited remotely, making it critical for organizations using vulnerable versions to upgrade as soon as possible.