4.3
CVSSv2

CVE-2014-4023

Published: 28/10/2014 Updated: 28/08/2015
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in tmui/dashboard/echo.jsp in the Configuration utility in F5 BIG-IP LTM, APM, ASM, GTM, and Link Controller 11.0.0 prior to 11.6.0 and 10.1.0 up to and including 10.2.4, AAM 11.4.0 prior to 11.6.0, AFM and PEM 11.3.0 prior to 11.6.0, Analytics 11.0.0 up to and including 11.5.1, Edge Gateway, WebAccelerator, and WOM 11.0.0 up to and including 11.3.0 and 10.1.0 up to and including 10.2.4, and PSM 11.0.0 up to and including 11.4.1 and 10.1.0 up to and including 10.2.4 and Enterprise Manager 3.0.0 up to and including 3.1.1 and 2.1.0 up to and including 2.3.0 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

f5 big-ip advanced firewall manager 11.5.1

f5 big-ip advanced firewall manager 11.5.0

f5 big-ip advanced firewall manager 11.4.1

f5 big-ip advanced firewall manager 11.3.0

f5 big-ip advanced firewall manager 11.4.0

f5 big-ip policy enforcement manager 11.4.0

f5 big-ip policy enforcement manager 11.5.0

f5 big-ip policy enforcement manager 11.5.1

f5 big-ip policy enforcement manager 11.3.0

f5 big-ip policy enforcement manager 11.4.1

f5 big-ip application security manager 10.2.1

f5 big-ip application security manager 10.2.3

f5 big-ip application security manager 11.4.0

f5 big-ip application security manager 11.5.0

f5 big-ip application security manager 10.1.0

f5 big-ip application security manager 11.5.1

f5 big-ip application security manager 11.0.0

f5 big-ip application security manager 11.1.0

f5 big-ip application security manager 11.2.0

f5 big-ip application security manager 11.2.1

f5 big-ip application security manager 10.2.0

f5 big-ip application security manager 10.2.2

f5 big-ip application security manager 10.2.4

f5 big-ip application security manager 11.3.0

f5 big-ip application security manager 11.4.1

f5 big-ip application acceleration manager 11.5.0

f5 big-ip application acceleration manager 11.4.0

f5 big-ip application acceleration manager 11.4.1

f5 big-ip application acceleration manager 11.5.1

f5 enterprise manager 2.2.0

f5 enterprise manager 2.3.0

f5 enterprise manager 3.0.0

f5 enterprise manager 3.1.0

f5 enterprise manager 3.1.1

f5 enterprise manager 2.1.0

f5 big-ip edge gateway 10.2.0

f5 big-ip edge gateway 11.2.0

f5 big-ip edge gateway 11.3.0

f5 big-ip edge gateway 10.2.2

f5 big-ip edge gateway 10.2.3

f5 big-ip edge gateway 10.2.4

f5 big-ip edge gateway 11.0.0

f5 big-ip edge gateway 10.1.0

f5 big-ip edge gateway 10.2.1

f5 big-ip edge gateway 11.1.0

f5 big-ip edge gateway 11.2.1

f5 big-ip global traffic manager 10.2.2

f5 big-ip global traffic manager 10.2.4

f5 big-ip global traffic manager 11.2.1

f5 big-ip global traffic manager 11.5.0

f5 big-ip global traffic manager 11.1.0

f5 big-ip global traffic manager 11.2.0

f5 big-ip global traffic manager 11.3.0

f5 big-ip global traffic manager 11.4.0

f5 big-ip global traffic manager 11.4.1

f5 big-ip global traffic manager 10.1.0

f5 big-ip global traffic manager 10.2.0

f5 big-ip global traffic manager 10.2.1

f5 big-ip global traffic manager 10.2.3

f5 big-ip global traffic manager 11.0.0

f5 big-ip global traffic manager 11.5.1

f5 big-ip link controller 10.2.1

f5 big-ip link controller 11.1.0

f5 big-ip link controller 11.4.1

f5 big-ip link controller 11.5.1

f5 big-ip link controller 11.2.0

f5 big-ip link controller 11.2.1

f5 big-ip link controller 11.3.0

f5 big-ip link controller 11.4.0

f5 big-ip link controller 10.1.0

f5 big-ip link controller 10.2.0

f5 big-ip link controller 10.2.2

f5 big-ip link controller 10.2.3

f5 big-ip link controller 10.2.4

f5 big-ip link controller 11.0.0

f5 big-ip link controller 11.5.0

f5 big-ip local traffic manager 10.1.0

f5 big-ip local traffic manager 10.2.4

f5 big-ip local traffic manager 11.5.1

f5 big-ip local traffic manager 11.5.0

f5 big-ip local traffic manager 11.1.0

f5 big-ip local traffic manager 11.2.0

f5 big-ip local traffic manager 11.3.0

f5 big-ip local traffic manager 11.4.0

f5 big-ip local traffic manager 10.2.0

f5 big-ip local traffic manager 10.2.1

f5 big-ip local traffic manager 10.2.2

f5 big-ip local traffic manager 10.2.3

f5 big-ip local traffic manager 11.2.1

f5 big-ip local traffic manager 11.0.0

f5 big-ip local traffic manager 11.4.1

f5 big-ip access policy manager 10.1.0

f5 big-ip access policy manager 10.2.4

f5 big-ip access policy manager 11.5.0

f5 big-ip access policy manager 11.4.0

f5 big-ip access policy manager 11.0.0

f5 big-ip access policy manager 11.3.0

f5 big-ip access policy manager 11.2.1

f5 big-ip access policy manager 11.2.0

f5 big-ip access policy manager 11.1.0

f5 big-ip access policy manager 10.2.0

f5 big-ip access policy manager 10.2.1

f5 big-ip access policy manager 10.2.2

f5 big-ip access policy manager 10.2.3

f5 big-ip access policy manager 11.5.1

f5 big-ip access policy manager 11.4.1

f5 big-ip protocol security module 10.1.0

f5 big-ip protocol security module 11.1.0

f5 big-ip protocol security module 11.2.1

f5 big-ip protocol security module 11.3.0

f5 big-ip protocol security module 11.4.0

f5 big-ip protocol security module 11.4.1

f5 big-ip protocol security module 10.2.1

f5 big-ip protocol security module 10.2.2

f5 big-ip protocol security module 10.2.4

f5 big-ip protocol security module 10.2.3

f5 big-ip protocol security module 10.2.0

f5 big-ip protocol security module 11.0.0

f5 big-ip protocol security module 11.2.0

f5 big-ip webaccelerator 10.1.0

f5 big-ip webaccelerator 10.2.1

f5 big-ip webaccelerator 10.2.3

f5 big-ip webaccelerator 11.2.1

f5 big-ip webaccelerator 10.2.4

f5 big-ip webaccelerator 11.0.0

f5 big-ip webaccelerator 11.1.0

f5 big-ip webaccelerator 11.2.0

f5 big-ip webaccelerator 10.2.0

f5 big-ip webaccelerator 10.2.2

f5 big-ip webaccelerator 11.3.0

f5 big-ip wan optimization manager 11.0.0

f5 big-ip wan optimization manager 11.2.0

f5 big-ip wan optimization manager 10.2.0

f5 big-ip wan optimization manager 10.2.1

f5 big-ip wan optimization manager 10.2.2

f5 big-ip wan optimization manager 10.2.3

f5 big-ip wan optimization manager 11.2.1

f5 big-ip wan optimization manager 11.3.0

f5 big-ip wan optimization manager 10.1.0

f5 big-ip wan optimization manager 10.2.4

f5 big-ip wan optimization manager 11.1.0

f5 big-ip analytics 11.4.0

f5 big-ip analytics 11.2.1

f5 big-ip analytics 11.2.0

f5 big-ip analytics 11.1.0

f5 big-ip analytics 11.0.0

f5 big-ip analytics 11.5.0

f5 big-ip analytics 11.5.1

f5 big-ip analytics 11.4.1

f5 big-ip analytics 11.3.0

Exploits

F5 BIG-IP versions 1151 and below suffer from a reflective cross site scripting vulnerability ...