CVE-2021-22993: XSS
On BIG-IP Advanced WAF and BIG-IP ASM versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, DOM-based XSS on DoS Profile properties page. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-22993?
CVE-2021-22993 has been classified as a High severity vulnerability due to its potential impact on the affected applications.
How do I fix CVE-2021-22993?
To fix CVE-2021-22993, update your F5 BIG-IP Advanced WAF and ASM to the latest versions as specified by the vendor.
What are the affected versions in CVE-2021-22993?
CVE-2021-22993 affects F5 BIG-IP Advanced WAF and ASM versions before 16.0.1.1, 15.1.2, 14.1.3.1, 13.1.3.6, and 12.1.5.3.
What type of vulnerability is CVE-2021-22993?
CVE-2021-22993 is a DOM-based Cross-Site Scripting (XSS) vulnerability that can be exploited through the DoS Profile properties page.
Does CVE-2021-22993 affect all versions of F5 BIG-IP products?
No, CVE-2021-22993 only affects specific versions of F5 BIG-IP Advanced WAF and ASM and not versions that have reached End of Software Development.