CVE-2020-27719

MEDIUM WAF: High
CVSS 6.1 Published: 2020-12-24
CWE-79

On BIG-IP 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.3, a cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility.

WAF Coverage Analysis

Cross-Site Scripting (XSS) High WAF Coverage

OWASP: A03:2021 Injection

941xxx - XSS / XXE

Affected Software

VendorProductVersion
f5big-ip_access_policy_manager14.1.0 - 14.1.3.1
f5big-ip_access_policy_manager15.0.0 - 15.1.1
f5big-ip_access_policy_manager16.0.0 - 16.0.1
f5big-ip_advanced_firewall_manager14.1.0 - 14.1.3.1
f5big-ip_advanced_firewall_manager15.0.0 - 15.1.1
f5big-ip_advanced_firewall_manager16.0.0 - 16.0.1
f5big-ip_advanced_web_application_firewall14.1.0 - 14.1.3.1
f5big-ip_advanced_web_application_firewall15.0.0 - 15.1.1
f5big-ip_advanced_web_application_firewall16.0.0 - 16.0.1
f5big-ip_analytics14.1.0 - 14.1.3.1

References

Back to CVE Database