On BIG-IP (AFM, ASM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a stored cross-site scripting vulnerability in AFM feed list. In the worst case, an attacker can store a CSRF which results in code execution as the admin user. The level of user role which can perform this attack are resource administrator and administrator.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-16195 On BIG-IP (AFM, ASM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a stored cross-site scripting vulnerability in AFM feed list. In the worst case, an attacker can store a CSRF which results in code execution as the admin user. The level of user role which can perform this attack are resource administrator and administrator.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: f5

Published:

Updated: 2024-08-04T20:23:22.353Z

Reserved: 2019-01-22T00:00:00

Link: CVE-2019-6636

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-07-03T19:15:13.160

Modified: 2024-11-21T04:46:51.323

Link: CVE-2019-6636

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.