Advisory

F5 BIG-IP® Configuration Utility Persistent Cross-Site Scripting Vulnerability

Dell SecureWorks Security Advisory SWRX-2012-007

Advisory Information

  • Title: F5 BIG-IP® Configuration Utility persistent cross-site scripting vulnerability
  • Advisory ID: SWRX-2012-007
  • Date published: Wednesday, October 2, 2012
  • CVE: CVE-2012-2975
  • CVSS v2 base score: 4.3
  • Date of last update: Wednesday, October 2, 2012
  • Vendors contacted: F5
  • Release mode: Coordinated
  • Discovered by: Roger Wemyss, Dell SecureWorks

Summary

A vulnerability exists in the BIG-IP® Configuration Utility due to improper sanitization of the “Top Requested URLs” table on the Overview: Traffic page. Malicious content is not properly sanitized before being stored and is later returned to an administrator in dynamically generated web content. Remote attackers could leverage this vulnerability to conduct persistent cross-site scripting attacks. When a user navigates to the Overview: Traffic page within the BIG-IP Configuration Utility, the content of the “Top Requested URLs” table is loaded into the affected JavaScript array and is executed in the user’s browser session. Successful exploitation may aid an attacker in retrieving session cookies, stealing recently submitted data, or launching further attacks.

Download the PDF

PGP Signature (PC Users: You may need to right click your mouse and select "Save As" or "Save Target As" and then open with Notepad)

SecureWorks CTU Public Key


ブログ記事一覧ページに戻る

今すぐ Taegis をお試しください

ご確認ください:Taegis がリスクを軽減し、既存のセキュリティ投資を最適化し、人材不足を解消することがどのようにできるかをデモでご覧ください。