DOM-Based XSS in F5 BIG-IP Advanced WAF and ASM Products
CVE-2021-22993
8.8HIGH
What is CVE-2021-22993?
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the properties page for DoS Profile in F5 BIG-IP Advanced WAF and ASM. This flaw affects specific versions prior to their respective patches, allowing attackers to manipulate the DOM of the affected web application. Such manipulation can lead to unauthorized actions being executed on behalf of users, making it crucial for administrators to apply the necessary updates to safeguard their systems.
Affected Version(s)
BIG-IP Advanced WAF and BIG-IP ASM 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3