imPC@ndo IT

Tracker / CVE-2014-3959

CVE-2014-3959

Medium 4.3

Cross-site scripting (XSS) vulnerability in list.jsp in the Configuration utility in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, GTM, and Link Controller 11.2.1 through 11.5.1, AAM 11.4.0 through 11.5.1 PEM 11.3.0 through 11.5.1, PSM 11.2.1 through 11.4.1, WebAccelerator and WOM 11.2.1 through 11.3.0, and Enterprise Manager 3.0.0 through 3.1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

Affected products and versions

f5 big-ip_access_policy_manager
f5 big-ip_advanced_firewall_manager
f5 big-ip_analytics
f5 big-ip_application_acceleration_manager
f5 big-ip_application_security_manager
f5 big-ip_edge_gateway
f5 big-ip_global_traffic_manager
f5 big-ip_link_controller
f5 big-ip_local_traffic_manager
f5 big-ip_policy_enforcement_manager
f5 big-ip_protocol_security_module
f5 big-ip_wan_optimization_manager
f5 big-ip_webaccelerator
f5 enterprise_manager

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References