CVE Database
/

CVE-2016-9257

Back to search

CVE-2016-9257

Published: May 9, 2017

Modified: Aug 6, 2024

PUBLISHED

Description

In F5 BIG-IP APM 12.0.0 through 12.1.2, non-authenticated users may be able to inject JavaScript into a request that will then be rendered and executed in the context of the Administrative user when the Administrative user is viewing the Access System Logs, allowing the non-authenticated user to carry out a Cross Site Scripting (XSS) attack against the Administrative user.

VendorProductVersions

F5 Networks, Inc.

BIG-IP APM

affected
12.0.0 through 12.1.2

References

1038416
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now