CVE-2018-5521Cross-site Scripting in F5 Big-ip Access Policy Manager

Severity
6.1MEDIUMNVD
EPSS
0.3%
top 42.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 1
Latest updateMay 14

Description

On F5 BIG-IP 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, carefully crafted URLs can be used to reflect arbitrary content into GeoIP lookup responses, potentially exposing clients to XSS.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages13 packages

NVDf5/big-ip_websafe11.5.111.5.5+3
NVDf5/big-ip_analytics11.5.111.5.5+3
NVDf5/big-ip_edge_gateway11.5.111.5.5+3
NVDf5/big-ip_webaccelerator11.5.111.5.5+3
NVDf5/big-ip_link_controller11.5.111.5.5+3

🔴Vulnerability Details

2
GHSA
GHSA-hm4q-f2xp-j2xx: On F5 BIG-IP 122022-05-14
CVEList
CVE-2018-5521: On F5 BIG-IP 122018-06-01

📋Vendor Advisories

1
F5
CVE-2018-5521: On F5 BIG-IP 122018-06-01

💬Community

1
Bugzilla
CVE-2018-1000039 mupdf: multiple use after free in the PDF parser2018-05-24
CVE-2018-5521 — Cross-site Scripting in F5 | cvebase