MEDIUM · 5.4

CVE-2016-7469

A stored cross-site scripting (XSS) vulnerability in the Configuration utility device name change page in BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, PSM, ...

Vulnerability Description

A stored cross-site scripting (XSS) vulnerability in the Configuration utility device name change page in BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, PSM, WebAccelerator, WOM and WebSafe version 12.0.0 - 12.1.2, 11.4.0 - 11.6.1, and 11.2.1 allows an authenticated user to inject arbitrary web script or HTML. Exploitation requires Resource Administrator or Administrator privileges, and it could cause the Configuration utility client to become unstable.

CVSS Score

5.4

MEDIUM

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
F5Big-Ip Local Traffic Manager11.2.1
F5Big-Ip Application Acceleration Manager11.4.0
F5Big-Ip Advanced Firewall Manager11.2.1
F5Big-Ip Analytics11.2.1
F5Big-Ip Access Policy Manager11.2.1
F5Big-Ip Application Security Manager11.2.1
F5Big-Ip Domain Name System12.0.0
F5Big-Ip Edge Gateway11.2.1
F5Big-Ip Global Traffic Manager11.2.1
F5Big-Ip Link Controller11.2.1
F5Big-Ip Policy Enforcement Manager11.4.0
F5Big-Ip Protocol Security Module11.4.0
F5Big-Ip Webaccelerator11.2.1
F5Big-Ip Websafe11.6.0
F5Big-Ip Wan Optimization Manager11.2.1
F5Enterprise Manager3.1.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-7469?

CVE-2016-7469 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A stored cross-site scripting (XSS) vulnerability in the Configuration utility device name change page in BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, PSM, ...

How severe is CVE-2016-7469?

CVE-2016-7469 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-7469?

Check the references section above for vendor advisories and patch information. Affected products include: F5 Big-Ip Local Traffic Manager, F5 Big-Ip Application Acceleration Manager, F5 Big-Ip Advanced Firewall Manager, F5 Big-Ip Analytics, F5 Big-Ip Access Policy Manager.