First published: Wed Oct 16 2024(Updated: )
A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ user interface that allows an attacker with the Administrator role to run JavaScript in the context of the currently logged-in user.
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP and BIG-IQ Centralized Management | =8.2.0 | 8.3.08.2.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of F5-K000141080 is critical due to its potential to allow an attacker to execute JavaScript in the context of the currently logged-in user.
To fix F5-K000141080, apply the latest security patches and updates provided by F5 for the affected BIG-IQ Centralized Management software.
F5-K000141080 affects users with the Administrator role on the BIG-IQ Centralized Management version 8.2.0.
The potential impacts of F5-K000141080 include unauthorized access to sensitive information and the execution of malicious actions within the authenticated session.
Mitigation measures for F5-K000141080 include limiting Administrator access and conducting regular security audits to identify and remediate vulnerabilities.