XSS Vulnerability in F5 BIG-IP and Enterprise Manager
CVE-2019-6599
6.1MEDIUM
Summary
An XSS vulnerability affects versions of F5 BIG-IP and Enterprise Manager, stemming from improper escaping of values in a configuration utility's page. Attackers could exploit this flaw to inject malicious scripts, which would manipulate JSON responses. This weakness poses a significant risk, as it allows unauthorized users to execute scripts in the context of a user's session, potentially leading to unauthorized access and data manipulation.
Affected Version(s)
BIG-IP APM; Enterprise Manager 11.6.1-11.6.3.2, 11.5.1-11.5.8
BIG-IP APM; Enterprise Manager EM 3.1.1
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved