vulnerability

F5 Networks: K97285349 (CVE-2016-7469): XSS vulnerability in the BIG-IP and Enterprise Manager Configuration utilities CVE-2016-7469

Severity
4
CVSS
(AV:N/AC:M/Au:S/C:N/I:P/A:N)
Published
01/04/2017
Added
02/16/2017
Modified
09/16/2019

Description

A stored cross-site scripting (XSS) vulnerability in the Configuration utility device name change page in BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, PSM, WebAccelerator, WOM and WebSafe version 12.0.0 - 12.1.2, 11.4.0 - 11.6.1, and 11.2.1 allows an authenticated user to inject arbitrary web script or HTML. Exploitation requires Resource Administrator or Administrator privileges, and it could cause the Configuration utility client to become unstable.

Solution

f5-big-ip-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.