Multiple F5 BIG-IP Products CVE-2019-6639 HTML Injection Vulnerability
BID:109064
CVE-2019-6639 |Info
Multiple F5 BIG-IP Products CVE-2019-6639 HTML Injection Vulnerability
| Bugtraq ID: | 109064 |
| Class: | Input Validation Error |
| CVE: |
CVE-2019-6639 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 02 2019 12:00AM |
| Updated: | Jul 02 2019 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
F5 BIG-IP PEM 14.1 F5 BIG-IP PEM 14.0 F5 BIG-IP PEM 13.1.1 F5 BIG-IP PEM 13.1 F5 BIG-IP PEM 13.0.1 F5 BIG-IP PEM 13.0 F5 BIG-IP PEM 12.1.4 F5 BIG-IP PEM 12.1.3 F5 BIG-IP PEM 12.1.2 F5 BIG-IP PEM 12.1.1 F5 BIG-IP PEM 11.6.3 F5 BIG-IP PEM 11.6.2 F5 BIG-IP PEM 11.6.1 F5 BIG-IP PEM 11.5.8 F5 BIG-IP PEM 11.5.7 F5 BIG-IP PEM 11.5.6 F5 BIG-IP PEM 11.5.3 F5 BIG-IP PEM 11.5.2 F5 BIG-IP PEM 11.5.1 F5 BIG-IP PEM 11.5 F5 BIG-IP PEM 14.1.0.5 F5 BIG-IP PEM 14.1.0.4 F5 BIG-IP PEM 14.1.0.3 F5 BIG-IP PEM 14.1.0.2 F5 BIG-IP PEM 14.1.0.1 F5 BIG-IP PEM 14.0.0.3 F5 BIG-IP PEM 13.1.1.4 F5 BIG-IP PEM 13.1.1.3 F5 BIG-IP PEM 13.1.1.2 F5 BIG-IP PEM 13.1.0.8 F5 BIG-IP PEM 13.1.0.6 F5 BIG-IP PEM 13.1.0.5 F5 BIG-IP PEM 13.1.0.4 F5 BIG-IP PEM 12.1.3.6 F5 BIG-IP PEM 12.1.3.4 F5 BIG-IP PEM 12.1.3.2 F5 BIG-IP PEM 12.1.0 F5 BIG-IP PEM 11.6.0 F5 BIG-IP PEM 11.5.5 F5 BIG-IP PEM 11.5.4 F5 BIG-IP AFM 14.1 F5 BIG-IP AFM 14.0 F5 BIG-IP AFM 13.1.1 F5 BIG-IP AFM 13.1 F5 BIG-IP AFM 13.0.1 F5 BIG-IP AFM 13.0 F5 BIG-IP AFM 12.1.4 F5 BIG-IP AFM 12.1.3 F5 BIG-IP AFM 12.1.2 F5 BIG-IP AFM 12.1.1 F5 BIG-IP AFM 11.6.3 F5 BIG-IP AFM 11.6.1 F5 BIG-IP AFM 11.5.8 F5 BIG-IP AFM 11.5.7 F5 BIG-IP AFM 11.5.6 F5 BIG-IP AFM 11.5.3 F5 BIG-IP AFM 11.5.2 F5 BIG-IP AFM 11.5.1 F5 BIG-IP AFM 11.5 F5 BIG-IP AFM 14.1.0.5 F5 BIG-IP AFM 14.1.0.4 F5 BIG-IP AFM 14.1.0.3 F5 BIG-IP AFM 14.1.0.2 F5 BIG-IP AFM 14.1.0.1 F5 BIG-IP AFM 14.0.0.3 F5 BIG-IP AFM 13.1.1.4 F5 BIG-IP AFM 13.1.1.3 F5 BIG-IP AFM 13.1.1.2 F5 BIG-IP AFM 13.1.0.8 F5 BIG-IP AFM 13.1.0.6 F5 BIG-IP AFM 13.1.0.5 F5 BIG-IP AFM 13.1.0.4 F5 BIG-IP AFM 12.1.3.7 F5 BIG-IP AFM 12.1.3.6 F5 BIG-IP AFM 12.1.3.4 F5 BIG-IP AFM 12.1.3.2 F5 BIG-IP AFM 12.1.0 F5 BIG-IP AFM 11.6.2 F5 BIG-IP AFM 11.6.0 F5 BIG-IP AFM 11.5.5 F5 BIG-IP AFM 11.5.4 |
| Not Vulnerable: |
F5 BIG-IP PEM 11.6.4 F5 BIG-IP PEM 11.5.9 F5 BIG-IP PEM 14.1.0.6 F5 BIG-IP PEM 14.0.0.5 F5 BIG-IP PEM 13.1.1.5 F5 BIG-IP PEM 12.1.4.1 F5 BIG-IP AFM 11.6.4 F5 BIG-IP AFM 11.5.9 F5 BIG-IP AFM 14.1.0.6 F5 BIG-IP AFM 14.0.0.5 F5 BIG-IP AFM 13.1.1.5 F5 BIG-IP AFM 12.1.4.1 |
Discussion
Multiple F5 BIG-IP Products CVE-2019-6639 HTML Injection Vulnerability
Multiple F5 BIG-IP Products are prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Multiple F5 BIG-IP Products are prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Exploit / POC
Multiple F5 BIG-IP Products CVE-2019-6639 HTML Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Multiple F5 BIG-IP Products CVE-2019-6639 HTML Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.