PT-2014-8945 · F5 · Application Security Manager+1
Publicado
2014-12-08
·
Atualizado
2021-05-03
·
CVE-2014-9342
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
F5 BIG-IP version 11.3.0
Description
A cross-site scripting (XSS) issue exists in the tree view feature of Application Security Manager (ASM) due to insufficient validation of user input. This allows remote attackers to inject arbitrary web script or HTML by accessing a crafted URL during automatic policy generation.
Recommendations
For F5 BIG-IP version 11.3.0, consider restricting access to the tree view feature in ASM until a fix is available. As a temporary workaround, avoid using the crafted URLs that could trigger automatic policy generation with malicious input.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Application Security Manager
F5 Big-Ip