CVE Database
/

CVE-2019-6599

Back to search

CVE-2019-6599

Published: Mar 13, 2019

Modified: Sep 16, 2024

PUBLISHED

Description

In BIG-IP 11.6.1-11.6.3.2 or 11.5.1-11.5.8, or Enterprise Manager 3.1.1, improper escaping of values in an undisclosed page of the configuration utility may result with an improper handling on the JSON response when it is injected by a malicious script via a remote cross-site scripting (XSS) attack.

VendorProductVersions

F5 Networks, Inc.

BIG-IP APM; Enterprise Manager

affected
11.6.1-11.6.3.2, 11.5.1-11.5.8
affected
EM 3.1.1

References

107420
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now