CVE-2022-27880: XSS
On F5 Traffix SDC 5.2.x versions prior to 5.2.2 and 5.1.x versions prior to 5.1.35, a stored Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the Traffix SDC Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-27880.
What is the severity level of CVE-2022-27880?
The severity level of CVE-2022-27880 is medium, with a severity value of 4.8.
What is the affected software version range?
The affected software versions are F5 Traffix SDC 5.2.x versions prior to 5.2.2 and 5.1.x versions prior to 5.1.35.
What is the CWE ID associated with this vulnerability?
The CWE ID associated with this vulnerability is CWE-79.
How can I fix CVE-2022-27880?
To mitigate this vulnerability, update your F5 Traffix SDC software to version 5.2.2 or 5.1.35.