CVE-2019-6599
MEDIUMBIG-IP 11.5.1-11.5.8 - Cross-Site Scripting in Configuration Utility
Title source: llmDescription
In BIG-IP 11.6.1-11.6.3.2 or 11.5.1-11.5.8, or Enterprise Manager 3.1.1, improper escaping of values in an undisclosed page of the configuration utility may result with an improper handling on the JSON response when it is injected by a malicious script via a remote cross-site scripting (XSS) attack.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://support.f5.com/csp/article/K46401178
Third Party Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/107420
Scores
CVSS v3
6.1
EPSS
0.0029
EPSS Percentile
52.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
f5/big-ip_access_policy_manager
11.5.1 - 11.5.8
Published
Mar 13, 2019
Tracked Since
Feb 18, 2026