cbcvebase.
CVE-2019-6636
published 2019-07-03

CVE-2019-6636: On BIG-IP (AFM, ASM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a stored cross-site scripting vulnerability in AFM…

high8.4CVSS 3.0
AVNACLPRHUIRSCCHIHAH
On BIG-IP (AFM, ASM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a stored cross-site scripting vulnerability in AFM feed list. In the worst case, an attacker can store a CSRF which results in code execution as the admin user. The level of user role which can perform this attack are resource administrator and administrator.

Affected

10 ranges
VendorProductVersion rangeFixed in
f5big-ip_advanced_firewall_manager>= 12.0.0 < 12.1.4.112.1.4.1
f5big-ip_advanced_firewall_manager>= 13.0.0 < 13.1.1.513.1.1.5
f5big-ip_advanced_firewall_manager>= 14.0.0 < 14.0.0.514.0.0.5
f5big-ip_advanced_firewall_manager>= 14.1.0 < 14.1.0.614.1.0.6
f5big-ip_afm
f5big-ip_application_security_manager>= 12.0.0 < 12.1.4.112.1.4.1
f5big-ip_application_security_manager>= 13.0.0 < 13.1.1.513.1.1.5
f5big-ip_application_security_manager>= 14.0.0 < 14.0.0.514.0.0.5
f5big-ip_application_security_manager>= 14.1.0 < 14.1.0.614.1.0.6
f5big-ip_asm