F5-K000134535: XSS
Published Aug 2, 2023
·Updated
A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user.
Affected Software
5 affected componentsFixes available
F5 BIG-IP>=17.0.0<=17.1.0
17.1.0.2
F5 BIG-IP>=16.1.0<=16.1.3
16.1.3.5
F5 BIG-IP>=15.1.0<=15.1.9
15.1.9.1
F5 BIG-IP>=14.1.0<=14.1.5
14.1.5.5
F5 BIG-IP>=13.1.0<=13.1.5
Event History
Aug 2, 2023
Advisory Published
via F5·12:58 PM
Frequently Asked Questions
1
What is the severity of F5-K000134535?
The F5-K000134535 vulnerability has a medium severity rating due to its cross-site scripting (XSS) impact.
2
How do I fix F5-K000134535?
To fix F5-K000134535, upgrade to the recommended patched versions provided by F5.
3
What type of vulnerability is F5-K000134535?
F5-K000134535 is a cross-site scripting (XSS) vulnerability affecting the BIG-IP Configuration utility.
4
Which versions of F5 BIG-IP are affected by F5-K000134535?
F5-K000134535 affects multiple versions of F5 BIG-IP from 13.1.0 to 17.1.0.
5
What can attackers do with F5-K000134535?
Attackers exploiting F5-K000134535 can execute JavaScript in the context of a logged-in user's session.