On F5 BIG-IP AFM 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, there is a Reflected Cross Site Scripting vulnerability in undisclosed TMUI page.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1041933 | vdb entry third party advisory |
https://support.f5.com/csp/article/K04524282 | vendor advisory |
http://www.securityfocus.com/bid/105733 | vdb entry third party advisory |