CVE-2018-15312Cross-site Scripting in F5 Big-ip Access Policy Manager

Severity
6.1MEDIUMNVD
EPSS
0.3%
top 50.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 19
Latest updateMay 14

Description

On F5 BIG-IP 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, a reflected Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an authenticated user to execute JavaScript for the currently logged-in user.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages13 packages

NVDf5/big-ip_analytics12.1.012.1.3.6+1
NVDf5/big-ip_edge_gateway12.1.012.1.3.6+1
NVDf5/big-ip_webaccelerator12.1.012.1.3.6+1
NVDf5/big-ip_link_controller12.1.012.1.3.6+1
NVDf5/big-ip_domain_name_system12.1.012.1.3.6+1

🔴Vulnerability Details

2
GHSA
GHSA-jc3v-9r6m-4q4v: On F5 BIG-IP 132022-05-14
CVEList
CVE-2018-15312: On F5 BIG-IP 132018-10-19

📋Vendor Advisories

1
F5
CVE-2018-15312: On F5 BIG-IP 132018-10-19
CVE-2018-15312 — Cross-site Scripting in F5 | cvebase