8
CVE-2024-31156 - BIG-IP Configuration utility XSS vulnerability
A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user.ย Note: Software versions which have reached End of Technical Support (EoTS) are not evaluateโฆ
6.1
CVE-2024-33604 - BIG-IP Configuration utility XSS vulnerability
A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user.ย Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
4.4
CVE-2024-28132 - BIG-IP NEXT CNF vulnerability
Exposure of Sensitive Information vulnerability exists in the GSLB container, which may allow an authenticated attacker with local access to view sensitive information.ย ย Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
5.9
CVE-2024-28889 - BIG-IP SSL vulnerability
When an SSL profile with alert timeout is configured with a non-default value on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate.ย ย Note: Software versions which have reached End of Technicalโฆ
7.4
CVE-2024-32049 - BIG-IP Next Central Manager vulnerability
BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials.ย Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
4.7
CVE-2024-27202 - BIG-IP TMUI XSS vulnerability
A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user.ย Note: Software versions which have reached End of Technical Support (EoTS) are not evaluโฆ
7.5
CVE-2024-25560 - TMM Vulnerability
When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
7.5
CVE-2024-33608 - BIG-IP IPsec vulnerability
When IPsec is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
7.4
CVE-2024-28883 - BIG-IP APM browser network access VPN client vulnerability
An origin validation vulnerability exists in BIG-IP APM browser network access VPN client for Windows, macOS and Linux which may allow an attacker to bypass F5 endpoint inspection. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
6.3
CVE-2024-4654 - BlueNet Technology Clinical Browsing System cloudInterface.php sql injection
A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1. It has been classified as critical. This affects an unknown part of the file /xds/cloudInterface.php. The manipulation of the argument INSTI_CODE leads to sql injection. It is possible to initiate the attack remotely. Tโฆ