F5 BIG-IP APM CVE-2019-6595 Cross Site Scripting Vulnerability
BID:107173
CVE-2019-6595 |Info
F5 BIG-IP APM CVE-2019-6595 Cross Site Scripting Vulnerability
| Bugtraq ID: | 107173 |
| Class: | Input Validation Error |
| CVE: |
CVE-2019-6595 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 26 2019 12:00AM |
| Updated: | Feb 26 2019 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
F5 BIG-IQ Centralized Management 4.6 F5 BIG-IP APM 11.6.3 F5 BIG-IP APM 11.6.2 HF1 F5 BIG-IP APM 11.6.2 F5 BIG-IP APM 11.6.1 HF2 F5 BIG-IP APM 11.6.1 HF1 F5 BIG-IP APM 11.6.1 F5 BIG-IP APM 11.6 HF8 F5 BIG-IP APM 11.6 HF7 F5 BIG-IP APM 11.6 HF6 F5 BIG-IP APM 11.6 HF5 F5 BIG-IP APM 11.6 HF4 F5 BIG-IP APM 11.6 HF3 F5 BIG-IP APM 11.5.7 F5 BIG-IP APM 11.5.6 F5 BIG-IP APM 11.5.5 F5 BIG-IP APM 11.5.4 HF3 F5 BIG-IP APM 11.5.4 HF2 F5 BIG-IP APM 11.5.4 HF1 F5 BIG-IP APM 11.5.3 HF2 F5 BIG-IP APM 11.5.3 F5 BIG-IP APM 11.5.2 HF1 F5 BIG-IP APM 11.5.2 F5 BIG-IP APM 11.5.1 HF11 F5 BIG-IP APM 11.5.1 HF10 F5 BIG-IP APM 11.5.1 F5 BIG-IP APM 11.6.0 F5 BIG-IP APM 11.5.4 F5 BIG-IP APM 11.5.3 HF1 F5 BIG-IP APM 11.5.1 HF6 |
| Not Vulnerable: | |
Discussion
F5 BIG-IP APM CVE-2019-6595 Cross Site Scripting Vulnerability
F5 BIG-IP APM is prone to a cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
F5 BIG-IP APM versions 4.6.0 and 11.5.1 through 11.6.3 are vulnerable.
F5 BIG-IP APM is prone to a cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
F5 BIG-IP APM versions 4.6.0 and 11.5.1 through 11.6.3 are vulnerable.
Exploit / POC
F5 BIG-IP APM CVE-2019-6595 Cross Site Scripting Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].