PT-2020-18803 · F5 · Big-Ip
Published
2020-07-01
·
Updated
2021-07-21
·
CVE-2020-5905
CVSS v2.0
6.0
Medium
| Vector | AV:N/AC:M/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
F5 BIG-IP versions 11.6.1 through 11.6.5.2
Description
The issue concerns the BIG-IP system Configuration utility, specifically the Network > WCCP page, where user-provided data is not properly sanitized before being displayed.
Recommendations
For versions 11.6.1 through 11.6.5.2, consider restricting access to the Network > WCCP page in the Configuration utility until a fix is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Big-Ip