CVE-2025-61933: BIG-IP APM cross-site scripting (XSS) vulnerability
A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of BIG-IP APM that allows an attacker to run JavaScript in the context of the targeted logged-out user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61933?
CVE-2025-61933 is a critical reflected cross-site scripting (XSS) vulnerability that can allow attackers to execute JavaScript in the context of targeted logged-out users.
How do I fix CVE-2025-61933?
To fix CVE-2025-61933, upgrade to the latest fixed versions of BIG-IP APM as recommended in the official advisory.
Who is affected by CVE-2025-61933?
CVE-2025-61933 affects users of F5 BIG-IP APM versions 17.5.1.317.1.3, 16.1.6.1, and 15.1.10.8 along with specified earlier versions.
What kind of attack exploits CVE-2025-61933?
CVE-2025-61933 can be exploited through reflected cross-site scripting, allowing attackers to run malicious scripts on victims' browsers.
Is CVE-2025-61933 an internal or external threat?
CVE-2025-61933 represents an external threat as it can be exploited by attackers targeting users visiting a vulnerable page from the outside.