CVE-2020-5889
published 2020-04-30CVE-2020-5889: On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, in BIG-IP APM portal access, a specially crafted HTTP request can lead to reflected XSS…
PriorityP426medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.72%
50.2th percentile
On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, in BIG-IP APM portal access, a specially crafted HTTP request can lead to reflected XSS after the BIG-IP APM system rewrites the HTTP response from the untrusted backend server and sends it to the client.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_access_policy_manager | 14.1.0 – 14.1.2.3 | — |
| f5 | big-ip_access_policy_manager | 15.0.0 – 15.0.1.2 | — |
| f5 | big-ip_access_policy_manager | 15.1.0 – 15.1.0.1 | — |
| f5 | big-ip_apm | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2020-5889: On versions 15
vendor_f5·2020-04-30·CVSS 5.4
CVE-2020-5889 [MEDIUM] CWE-79 CVE-2020-5889: On versions 15
CVE-2020-5889: On versions 15
On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, in BIG-IP APM portal access, a specially crafted HTTP request can lead to reflected XSS after the BIG-IP APM system rewrites the HTTP response from the untrusted backend server and sends it to the client.
Affected Products: BIG-IP APM
Affected Versions: 14.1.0 - 14.1.2.3; 15.0.0 - 15.0.1.2; 15.1.0 - 15.1.0.1
F5 Advisory Articles: K24415506
F5 References: https://support.f5.com/csp/article/K24415506
GHSA
GHSA-cj43-7274-vrw4: On versions 15
ghsa_unreviewed·2022-05-24
CVE-2020-5889 [LOW] GHSA-cj43-7274-vrw4: On versions 15
On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, in BIG-IP APM portal access, a specially crafted HTTP request can lead to reflected XSS after the BIG-IP APM system rewrites the HTTP response from the untrusted backend server and sends it to the client.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-04-30
Published