Cross-Site Scripting Vulnerability in BIG-IP AFM by F5 Networks
CVE-2021-22983
5.4MEDIUM
What is CVE-2021-22983?
On specific versions of the BIG-IP Application Security Manager, authenticated users can fall prey to a cross-site scripting attack through maliciously-crafted URLs when accessing the Configuration utility. This vulnerability exposes sensitive data and could allow attackers to manipulate user sessions or gain unauthorized information. Note that affected software versions that have reached End of Software Development are not considered in the evaluation.
Affected Version(s)
BIG-IP AFM 15.1.x before 15.1.1, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.5