First published: Wed Aug 26 2020(Updated: )
In versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, and 14.1.0-14.1.2.6, BIG-IP ASM Configuration utility Stored-Cross Site Scripting.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Application Security Manager | >=14.1.0<14.1.2.7 | |
F5 Application Security Manager | >=15.0.0<15.0.1.4 | |
F5 Application Security Manager | >=15.1.0<15.1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5927 is rated as high severity due to the risk of stored cross-site scripting in affected versions of BIG-IP ASM Configuration utility.
To fix CVE-2020-5927, upgrade your F5 BIG-IP Application Security Manager to a version that is not vulnerable, such as 14.1.2.7 or later, 15.0.1.4 or later, or 15.1.0.5 or later.
CVE-2020-5927 affects F5 BIG-IP Application Security Manager versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, and 14.1.0-14.1.2.6.
CVE-2020-5927 is a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into the application.
Yes, CVE-2020-5927 can be exploited remotely, making it critical for organizations using vulnerable versions to upgrade as soon as possible.