XSS Vulnerability in F5 BIG-IP and Enterprise Manager
CVE-2019-6599

6.1MEDIUM

Key Information:

Vendor
F5
Vendor
CVE Published:
11 March 2019

Summary

An XSS vulnerability affects versions of F5 BIG-IP and Enterprise Manager, stemming from improper escaping of values in a configuration utility's page. Attackers could exploit this flaw to inject malicious scripts, which would manipulate JSON responses. This weakness poses a significant risk, as it allows unauthorized users to execute scripts in the context of a user's session, potentially leading to unauthorized access and data manipulation.

Affected Version(s)

BIG-IP APM; Enterprise Manager 11.6.1-11.6.3.2, 11.5.1-11.5.8

BIG-IP APM; Enterprise Manager EM 3.1.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.