cbcvebase.
CVE-2014-3959
published 2014-06-03

CVE-2014-3959: Cross-site scripting (XSS) vulnerability in list.jsp in the Configuration utility in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, GTM, and Link Controller 11.2.1…

medium4.3CVSS 3.1
AVNACMAuNCNIPAN
Cross-site scripting (XSS) vulnerability in list.jsp in the Configuration utility in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, GTM, and Link Controller 11.2.1 through 11.5.1, AAM 11.4.0 through 11.5.1 PEM 11.3.0 through 11.5.1, PSM 11.2.1 through 11.4.1, WebAccelerator and WOM 11.2.1 through 11.3.0, and Enterprise Manager 3.0.0 through 3.1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_advanced_firewall_manager
f5big-ip_advanced_firewall_manager
f5big-ip_analytics
f5big-ip_analytics
f5big-ip_application_acceleration_manager
f5big-ip_application_acceleration_manager
f5big-ip_application_security_manager
f5big-ip_application_security_manager
f5big-ip_edge_gateway
f5big-ip_edge_gateway
f5big-ip_global_traffic_manager
f5big-ip_global_traffic_manager
f5big-ip_link_controller
f5big-ip_link_controller
f5big-ip_local_traffic_manager
f5big-ip_local_traffic_manager
f5big-ip_policy_enforcement_manager
f5big-ip_policy_enforcement_manager
f5big-ip_protocol_security_module
f5big-ip_protocol_security_module
f5big-ip_wan_optimization_manager
f5big-ip_wan_optimization_manager
f5big-ip_webaccelerator