Reflected Cross-Site Scripting Vulnerability in F5 BIG-IP APM and Guided Configuration
CVE-2022-27230
7.5HIGH
Key Information:
- Vendor
- F5
- Vendor
- CVE Published:
- 5 May 2022
Summary
A reflected cross-site scripting (XSS) vulnerability exists in F5 BIG-IP APM and Guided Configuration. This flaw allows attackers to execute malicious JavaScript in the browser of a logged-in user, potentially compromising sensitive information or session data. The vulnerability affects numerous versions of F5 BIG-IP APM from 16.1.x down to 11.6.x and all prior versions of F5 BIG-IP Guided Configuration before 9.0. Users are advised to apply necessary security patches and follow best practices to mitigate the risk.
Affected Version(s)
BIG-IP APM 16.1.x
BIG-IP APM 15.1.x
BIG-IP APM 14.1.x
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved