PT-2014-5635 · F5 · Gtm+12

Published

2014-06-03

·

Updated

2016-10-19

·

CVE-2014-3959

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions F5 BIG-IP LTM, AFM, Analytics, APM, ASM, GTM, and Link Controller versions 11.2.1 through 11.5.1 F5 AAM versions 11.4.0 through 11.5.1 F5 PEM versions 11.3.0 through 11.5.1 F5 PSM versions 11.2.1 through 11.4.1 F5 WebAccelerator and WOM versions 11.2.1 through 11.3.0 F5 Enterprise Manager versions 3.0.0 through 3.1.1
Description A cross-site scripting (XSS) issue exists in the list.jsp file of the Configuration utility, allowing remote attackers to inject arbitrary web script or HTML via unspecified parameters.
Recommendations For F5 BIG-IP LTM, AFM, Analytics, APM, ASM, GTM, and Link Controller versions 11.2.1 through 11.5.1, update to a version outside of this range to resolve the issue. For F5 AAM versions 11.4.0 through 11.5.1, update to a version outside of this range to resolve the issue. For F5 PEM versions 11.3.0 through 11.5.1, update to a version outside of this range to resolve the issue. For F5 PSM versions 11.2.1 through 11.4.1, update to a version outside of this range to resolve the issue. For F5 WebAccelerator and WOM versions 11.2.1 through 11.3.0, update to a version outside of this range to resolve the issue. For F5 Enterprise Manager versions 3.0.0 through 3.1.1, update to a version outside of this range to resolve the issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-3959

Affected Products

Aam
Afm
Apm
Asm
Analytics
Big-Ip Ltm
Enterprise Manager
Gtm
Link Controller
Pem
Psm
Wom
Webaccelerator