F5-K000133474: XSS
A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000133474?
The severity of F5-K000133474 is critical as it involves a reflected cross-site scripting (XSS) vulnerability.
How do I fix F5-K000133474?
To fix F5-K000133474, it's recommended to upgrade the BIG-IP to the latest patched version.
Which versions of BIG-IP are affected by F5-K000133474?
F5-K000133474 affects BIG-IP versions 17.0.0 to 17.1.0.2, 16.1.0 to 16.1.3.5, 15.1.0 to 15.1.9.1, 14.1.0 to 14.1.5.5, and 13.1.0 to 13.1.5.
What type of attack can F5-K000133474 facilitate?
F5-K000133474 can facilitate reflected cross-site scripting (XSS) attacks, allowing the execution of JavaScript in the context of the logged-in user.
Is user authentication affected by F5-K000133474?
Yes, F5-K000133474 affects users who are currently logged in, as it allows attackers to run scripts in their session.