DOM-Based XSS in F5 BIG-IP Advanced WAF and ASM Products
CVE-2021-22993
8.8HIGH
Summary
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the properties page for DoS Profile in F5 BIG-IP Advanced WAF and ASM. This flaw affects specific versions prior to their respective patches, allowing attackers to manipulate the DOM of the affected web application. Such manipulation can lead to unauthorized actions being executed on behalf of users, making it crucial for administrators to apply the necessary updates to safeguard their systems.
Affected Version(s)
BIG-IP Advanced WAF and BIG-IP ASM 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved