PT-2020-18803 · F5 · Big-Ip

Published

2020-07-01

·

Updated

2021-07-21

·

CVE-2020-5905

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions F5 BIG-IP versions 11.6.1 through 11.6.5.2
Description The issue concerns the BIG-IP system Configuration utility, specifically the Network > WCCP page, where user-provided data is not properly sanitized before being displayed.
Recommendations For versions 11.6.1 through 11.6.5.2, consider restricting access to the Network > WCCP page in the Configuration utility until a fix is available.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5905

Affected Products

Big-Ip