F5-K000138520: XSS
A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000138520?
The severity of F5-K000138520 is categorized as high due to the potential for DOM-based cross-site scripting leading to unauthorized access within the application.
How do I fix F5-K000138520?
To remediate F5-K000138520, update your F5 BIG-IP or BIG-IQ to the specified patched versions outlined in the advisory.
What symptoms indicate the presence of F5-K000138520?
Symptoms of F5-K000138520 may include unexpected JavaScript execution or abnormal application behavior when using the BIG-IP Configuration utility.
Who is affected by F5-K000138520?
F5-K000138520 affects users of F5 BIG-IP and BIG-IQ Centralized Management running specific versions of the software listed in the advisory.
Is F5-K000138520 exploitable remotely?
Yes, F5-K000138520 is potentially exploitable remotely, allowing attackers to execute scripts in the context of an authenticated user session.