CVE-2021-23027: XSS
On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, and 14.1.x before 14.1.4.3, a DOM based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-23027.
What is the severity level of CVE-2021-23027?
CVE-2021-23027 has a severity level of medium (6.1).
Which software versions are affected by CVE-2021-23027?
Versions 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, and 14.1.x before 14.1.4.3 of the F5 BIG-IP Access Policy Manager, F5 BIG-IP Advanced Firewall Manager, F5 Big-ip Advanced Web Application Firewall, F5 BIG-IP Analytics, F5 Big-ip Application Acceleration Manager, F5 BIG-IP Application Security Manager, F5 Big-ip Ddos Hybrid Defender, F5 Big-ip Domain Name System, F5 Big-ip Fraud Protection Service, F5 Big-ip Global Traffic Manager, F5 Big-ip Link Controller, F5 Big-ip Local Traffic Manager, F5 Big-ip Policy Enforcement Manager, and F5 Big-ip Ssl Orchestrator are affected.
What is the vulnerability description of CVE-2021-23027?
CVE-2021-23027 is a DOM based cross-site scripting (XSS) vulnerability that allows an attacker to execute JavaScript in the context of the currently logged-in user.
How can I fix CVE-2021-23027?
To fix CVE-2021-23027, upgrade to version 16.0.1.2, 15.1.3.1, or 14.1.4.3 of the affected software.