cbcvebase.
CVE-2018-15312
published 2018-10-19

CVE-2018-15312: On F5 BIG-IP 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, a reflected Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP…

medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
On F5 BIG-IP 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, a reflected Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an authenticated user to execute JavaScript for the currently logged-in user.

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
f5big-ip_aam
f5big-ip_access_policy_manager12.1.0 – 12.1.3.6
f5big-ip_access_policy_manager13.0.0 – 13.1.1.1
f5big-ip_advanced_firewall_manager12.1.0 – 12.1.3.6
f5big-ip_advanced_firewall_manager13.0.0 – 13.1.1.1
f5big-ip_afm
f5big-ip_analytics
f5big-ip_analytics12.1.0 – 12.1.3.6
f5big-ip_analytics13.0.0 – 13.1.1.1
f5big-ip_apm
f5big-ip_application_acceleration_manager12.1.0 – 12.1.3.6
f5big-ip_application_acceleration_manager13.0.0 – 13.1.1.1
f5big-ip_application_security_manager12.1.0 – 12.1.3.6
f5big-ip_application_security_manager13.0.0 – 13.1.1.1
f5big-ip_asm
f5big-ip_dns
f5big-ip_domain_name_system12.1.0 – 12.1.3.6
f5big-ip_domain_name_system13.0.0 – 13.1.1.1
f5big-ip_edge_gateway
f5big-ip_edge_gateway12.1.0 – 12.1.3.6
f5big-ip_edge_gateway13.0.0 – 13.1.1.1
f5big-ip_fps
f5big-ip_fraud_protection_service12.1.0 – 12.1.3.6
f5big-ip_fraud_protection_service13.0.0 – 13.1.1.1
f5big-ip_global_traffic_manager12.1.0 – 12.1.3.6