PT-2021-15316 · F5 · Big-Ip Afm

Published

2021-02-12

·

Updated

2021-02-18

·

CVE-2021-22983

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions BIG-IP AFM versions 13.1.x through 13.1.3.4 BIG-IP AFM versions 14.1.x through 14.1.3.0 BIG-IP AFM versions 15.1.x through 15.1.0
Description The issue allows authenticated users accessing the Configuration utility for AFM to be vulnerable to a cross-site scripting attack if they attempt to access a maliciously-crafted URL.
Recommendations For BIG-IP AFM versions 13.1.x through 13.1.3.4, update to version 13.1.3.5 or later. For BIG-IP AFM versions 14.1.x through 14.1.3.0, update to version 14.1.3.1 or later. For BIG-IP AFM versions 15.1.x through 15.1.0, update to version 15.1.1 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-22983

Affected Products

Big-Ip Afm