A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of BIG-IP APM that allows an attacker to run JavaScript in the context of the targeted logged-out user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
2025-10-15T16:15:35.583
2025-10-21T12:12:54.180
Analyzed
CVSSv3.1: 6.1 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | f5 | big-ip_access_policy_manager | < 15.1.10.8 | Yes |
| Application | f5 | big-ip_access_policy_manager | < 16.1.6.1 | Yes |
| Application | f5 | big-ip_access_policy_manager | < 17.1.3 | Yes |
| Application | f5 | big-ip_access_policy_manager | < 17.5.1.3 | Yes |