PT-2021-15377 · F5 · Big-Ip Apm
Published
2021-09-27
·
Updated
2021-10-04
·
CVE-2021-23054
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
BIG-IP APM versions 11.6.x
BIG-IP APM versions 12.1.x
BIG-IP APM versions 13.1.x
BIG-IP APM versions 14.1.x through 14.1.4.4
BIG-IP APM versions 15.1.x through 15.1.4
BIG-IP APM versions 16.x through 16.1.0
Description
A reflected cross-site scripting (XSS) issue exists in the resource information page for authenticated users when a full webtop is configured on the BIG-IP APM system. This occurs due to insufficient input validation, allowing an attacker to inject malicious scripts. The vulnerability can be exploited when a user clicks on a specially crafted link.
Recommendations
For versions 11.6.x, consider disabling the resource information page for authenticated users until a patch is available.
For versions 12.1.x, restrict access to the resource information page to minimize the risk of exploitation.
For versions 13.1.x, avoid using the full webtop configuration until the issue is resolved.
For versions 14.1.x through 14.1.4.4, update to version 14.1.4.4 or later.
For versions 15.1.x through 15.1.4, update to version 15.1.4 or later.
For versions 16.x through 16.1.0, update to version 16.1.0 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Big-Ip Apm