Reflected Cross-Site Scripting Vulnerability in F5 BIG-IP APM and Guided Configuration
CVE-2022-27230

7.5HIGH

Key Information:

Vendor
F5
Vendor
CVE Published:
5 May 2022

Summary

A reflected cross-site scripting (XSS) vulnerability exists in F5 BIG-IP APM and Guided Configuration. This flaw allows attackers to execute malicious JavaScript in the browser of a logged-in user, potentially compromising sensitive information or session data. The vulnerability affects numerous versions of F5 BIG-IP APM from 16.1.x down to 11.6.x and all prior versions of F5 BIG-IP Guided Configuration before 9.0. Users are advised to apply necessary security patches and follow best practices to mitigate the risk.

Affected Version(s)

BIG-IP APM 16.1.x

BIG-IP APM 15.1.x

BIG-IP APM 14.1.x

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.