CVE Database
/

CVE-2018-5521

Back to search

CVE-2018-5521

Published: Jun 1, 2018

Modified: Sep 17, 2024

PUBLISHED

Description

On F5 BIG-IP 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, carefully crafted URLs can be used to reflect arbitrary content into GeoIP lookup responses, potentially exposing clients to XSS.

VendorProductVersions

F5 Networks, Inc.

BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, FPS, GTM, Link Controller, PEM, WebAccelerator)

affected
12.1.0-12.1.3.1
affected
11.6.1-11.6.3.1
affected
11.5.1-11.5.5
affected
11.2.1

References

1041021
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now