CVE-2021-23054: XSS
On version 16.x before 16.1.0, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, a reflected cross-site scripting (XSS) vulnerability exists in the resource information page for authenticated users when a full webtop is configured on the BIG-IP APM system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-23054?
CVE-2021-23054 is classified as a reflected cross-site scripting (XSS) vulnerability that affects multiple versions of F5 Big-IP Access Policy Manager.
How do I fix CVE-2021-23054?
To mitigate CVE-2021-23054, upgrade to F5 Big-IP Access Policy Manager versions 11.6.5, 12.1.6, 13.1.4, 14.1.4.4, 15.1.4, or 16.1.0 or later.
What are the affected versions for CVE-2021-23054?
CVE-2021-23054 affects F5 Big-IP Access Policy Manager versions 11.6.x, 12.1.x, 13.1.x, 14.1.x, 15.1.x prior to 15.1.4, and 16.x prior to 16.1.0.
Who is primarily affected by CVE-2021-23054?
Authenticated users of the F5 Big-IP Access Policy Manager are primarily affected by CVE-2021-23054.
What type of vulnerability is CVE-2021-23054?
CVE-2021-23054 is a reflected cross-site scripting (XSS) vulnerability.