Lucene search

K
cveMitreCVE-2014-4023
HistoryOct 28, 2014 - 2:55 p.m.

CVE-2014-4023

2014-10-2814:55:05
CWE-79
mitre
web.nvd.nist.gov
32
cve-2014-4023
cross-site scripting
xss
f5 big-ip
security vulnerability
web security

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

60.8%

Cross-site scripting (XSS) vulnerability in tmui/dashboard/echo.jsp in the Configuration utility in F5 BIG-IP LTM, APM, ASM, GTM, and Link Controller 11.0.0 before 11.6.0 and 10.1.0 through 10.2.4, AAM 11.4.0 before 11.6.0, AFM and PEM 11.3.0 before 11.6.0, Analytics 11.0.0 through 11.5.1, Edge Gateway, WebAccelerator, and WOM 11.0.0 through 11.3.0 and 10.1.0 through 10.2.4, and PSM 11.0.0 through 11.4.1 and 10.1.0 through 10.2.4 and Enterprise Manager 3.0.0 through 3.1.1 and 2.1.0 through 2.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected configurations

Nvd
Node
f5big-ip_advanced_firewall_managerMatch11.3.0
OR
f5big-ip_advanced_firewall_managerMatch11.4.0
OR
f5big-ip_advanced_firewall_managerMatch11.4.1
OR
f5big-ip_advanced_firewall_managerMatch11.5.0
OR
f5big-ip_advanced_firewall_managerMatch11.5.1
Node
f5big-ip_policy_enforcement_managerMatch11.3.0
OR
f5big-ip_policy_enforcement_managerMatch11.4.0
OR
f5big-ip_policy_enforcement_managerMatch11.4.1
OR
f5big-ip_policy_enforcement_managerMatch11.5.0
OR
f5big-ip_policy_enforcement_managerMatch11.5.1
Node
f5big-ip_application_security_managerMatch10.1.0
OR
f5big-ip_application_security_managerMatch10.2.0
OR
f5big-ip_application_security_managerMatch10.2.1
OR
f5big-ip_application_security_managerMatch10.2.2
OR
f5big-ip_application_security_managerMatch10.2.3
OR
f5big-ip_application_security_managerMatch10.2.4
OR
f5big-ip_application_security_managerMatch11.0.0
OR
f5big-ip_application_security_managerMatch11.1.0
OR
f5big-ip_application_security_managerMatch11.2.0
OR
f5big-ip_application_security_managerMatch11.2.1
OR
f5big-ip_application_security_managerMatch11.3.0
OR
f5big-ip_application_security_managerMatch11.4.0
OR
f5big-ip_application_security_managerMatch11.4.1
OR
f5big-ip_application_security_managerMatch11.5.0
OR
f5big-ip_application_security_managerMatch11.5.1
Node
f5big-ip_application_acceleration_managerMatch11.4.0
OR
f5big-ip_application_acceleration_managerMatch11.4.1
OR
f5big-ip_application_acceleration_managerMatch11.5.0
OR
f5big-ip_application_acceleration_managerMatch11.5.1
Node
f5enterprise_managerMatch3.0.0
OR
f5enterprise_managerMatch3.1.0
OR
f5enterprise_managerMatch3.1.1
OR
f5enterprise_managerMatch2.1.0
OR
f5enterprise_managerMatch2.2.0
OR
f5enterprise_managerMatch2.3.0
Node
f5big-ip_edge_gatewayMatch10.1.0
OR
f5big-ip_edge_gatewayMatch10.2.0
OR
f5big-ip_edge_gatewayMatch10.2.1
OR
f5big-ip_edge_gatewayMatch10.2.2
OR
f5big-ip_edge_gatewayMatch10.2.3
OR
f5big-ip_edge_gatewayMatch10.2.4
OR
f5big-ip_edge_gatewayMatch11.0.0
OR
f5big-ip_edge_gatewayMatch11.1.0
OR
f5big-ip_edge_gatewayMatch11.2.0
OR
f5big-ip_edge_gatewayMatch11.2.1
OR
f5big-ip_edge_gatewayMatch11.3.0
Node
f5big-ip_global_traffic_managerMatch10.1.0
OR
f5big-ip_global_traffic_managerMatch10.2.0
OR
f5big-ip_global_traffic_managerMatch10.2.1
OR
f5big-ip_global_traffic_managerMatch10.2.2
OR
f5big-ip_global_traffic_managerMatch10.2.3
OR
f5big-ip_global_traffic_managerMatch10.2.4
OR
f5big-ip_global_traffic_managerMatch11.0.0
OR
f5big-ip_global_traffic_managerMatch11.1.0
OR
f5big-ip_global_traffic_managerMatch11.2.0
OR
f5big-ip_global_traffic_managerMatch11.2.1
OR
f5big-ip_global_traffic_managerMatch11.3.0
OR
f5big-ip_global_traffic_managerMatch11.4.0
OR
f5big-ip_global_traffic_managerMatch11.4.1
OR
f5big-ip_global_traffic_managerMatch11.5.0
OR
f5big-ip_global_traffic_managerMatch11.5.1
Node
f5big-ip_link_controllerMatch10.1.0
OR
f5big-ip_link_controllerMatch10.2.0
OR
f5big-ip_link_controllerMatch10.2.1
OR
f5big-ip_link_controllerMatch10.2.2
OR
f5big-ip_link_controllerMatch10.2.3
OR
f5big-ip_link_controllerMatch10.2.4
OR
f5big-ip_link_controllerMatch11.0.0
OR
f5big-ip_link_controllerMatch11.1.0
OR
f5big-ip_link_controllerMatch11.2.0
OR
f5big-ip_link_controllerMatch11.2.1
OR
f5big-ip_link_controllerMatch11.3.0
OR
f5big-ip_link_controllerMatch11.4.0
OR
f5big-ip_link_controllerMatch11.4.1
OR
f5big-ip_link_controllerMatch11.5.0
OR
f5big-ip_link_controllerMatch11.5.1
Node
f5big-ip_local_traffic_managerMatch10.1.0
OR
f5big-ip_local_traffic_managerMatch10.2.0
OR
f5big-ip_local_traffic_managerMatch10.2.1
OR
f5big-ip_local_traffic_managerMatch10.2.2
OR
f5big-ip_local_traffic_managerMatch10.2.3
OR
f5big-ip_local_traffic_managerMatch10.2.4
OR
f5big-ip_local_traffic_managerMatch11.0.0
OR
f5big-ip_local_traffic_managerMatch11.1.0
OR
f5big-ip_local_traffic_managerMatch11.2.0
OR
f5big-ip_local_traffic_managerMatch11.2.1
OR
f5big-ip_local_traffic_managerMatch11.3.0
OR
f5big-ip_local_traffic_managerMatch11.4.0
OR
f5big-ip_local_traffic_managerMatch11.4.1
OR
f5big-ip_local_traffic_managerMatch11.5.0
OR
f5big-ip_local_traffic_managerMatch11.5.1
Node
f5big-ip_access_policy_managerMatch10.1.0
OR
f5big-ip_access_policy_managerMatch10.2.0
OR
f5big-ip_access_policy_managerMatch10.2.1
OR
f5big-ip_access_policy_managerMatch10.2.2
OR
f5big-ip_access_policy_managerMatch10.2.3
OR
f5big-ip_access_policy_managerMatch10.2.4
OR
f5big-ip_access_policy_managerMatch11.0.0
OR
f5big-ip_access_policy_managerMatch11.1.0
OR
f5big-ip_access_policy_managerMatch11.2.0
OR
f5big-ip_access_policy_managerMatch11.2.1
OR
f5big-ip_access_policy_managerMatch11.3.0
OR
f5big-ip_access_policy_managerMatch11.4.0
OR
f5big-ip_access_policy_managerMatch11.4.1
OR
f5big-ip_access_policy_managerMatch11.5.0
OR
f5big-ip_access_policy_managerMatch11.5.1
Node
f5big-ip_protocol_security_moduleMatch10.1.0
OR
f5big-ip_protocol_security_moduleMatch10.2.0
OR
f5big-ip_protocol_security_moduleMatch10.2.1
OR
f5big-ip_protocol_security_moduleMatch10.2.2
OR
f5big-ip_protocol_security_moduleMatch10.2.3
OR
f5big-ip_protocol_security_moduleMatch10.2.4
OR
f5big-ip_protocol_security_moduleMatch11.0.0
OR
f5big-ip_protocol_security_moduleMatch11.1.0
OR
f5big-ip_protocol_security_moduleMatch11.2.0
OR
f5big-ip_protocol_security_moduleMatch11.2.1
OR
f5big-ip_protocol_security_moduleMatch11.3.0
OR
f5big-ip_protocol_security_moduleMatch11.4.0
OR
f5big-ip_protocol_security_moduleMatch11.4.1
Node
f5big-ip_webacceleratorMatch10.1.0
OR
f5big-ip_webacceleratorMatch10.2.0
OR
f5big-ip_webacceleratorMatch10.2.1
OR
f5big-ip_webacceleratorMatch10.2.2
OR
f5big-ip_webacceleratorMatch10.2.3
OR
f5big-ip_webacceleratorMatch10.2.4
OR
f5big-ip_webacceleratorMatch11.0.0
OR
f5big-ip_webacceleratorMatch11.1.0
OR
f5big-ip_webacceleratorMatch11.2.0
OR
f5big-ip_webacceleratorMatch11.2.1
OR
f5big-ip_webacceleratorMatch11.3.0
Node
f5big-ip_wan_optimization_managerMatch10.1.0
OR
f5big-ip_wan_optimization_managerMatch10.2.0
OR
f5big-ip_wan_optimization_managerMatch10.2.1
OR
f5big-ip_wan_optimization_managerMatch10.2.2
OR
f5big-ip_wan_optimization_managerMatch10.2.3
OR
f5big-ip_wan_optimization_managerMatch10.2.4
OR
f5big-ip_wan_optimization_managerMatch11.0.0
OR
f5big-ip_wan_optimization_managerMatch11.1.0
OR
f5big-ip_wan_optimization_managerMatch11.2.0
OR
f5big-ip_wan_optimization_managerMatch11.2.1
OR
f5big-ip_wan_optimization_managerMatch11.3.0
Node
f5big-ip_analyticsMatch11.0.0
OR
f5big-ip_analyticsMatch11.1.0
OR
f5big-ip_analyticsMatch11.2.0
OR
f5big-ip_analyticsMatch11.2.1
OR
f5big-ip_analyticsMatch11.3.0
OR
f5big-ip_analyticsMatch11.4.0
OR
f5big-ip_analyticsMatch11.4.1
OR
f5big-ip_analyticsMatch11.5.0
OR
f5big-ip_analyticsMatch11.5.1
VendorProductVersionCPE
f5big-ip_advanced_firewall_manager11.3.0cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.3.0:*:*:*:*:*:*:*
f5big-ip_advanced_firewall_manager11.4.0cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.4.0:*:*:*:*:*:*:*
f5big-ip_advanced_firewall_manager11.4.1cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.4.1:*:*:*:*:*:*:*
f5big-ip_advanced_firewall_manager11.5.0cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.5.0:*:*:*:*:*:*:*
f5big-ip_advanced_firewall_manager11.5.1cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.5.1:*:*:*:*:*:*:*
f5big-ip_policy_enforcement_manager11.3.0cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.3.0:*:*:*:*:*:*:*
f5big-ip_policy_enforcement_manager11.4.0cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.4.0:*:*:*:*:*:*:*
f5big-ip_policy_enforcement_manager11.4.1cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.4.1:*:*:*:*:*:*:*
f5big-ip_policy_enforcement_manager11.5.0cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.5.0:*:*:*:*:*:*:*
f5big-ip_policy_enforcement_manager11.5.1cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.5.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 1501

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

60.8%