vendor:
BIG-IP
by:
SecurityFocus
8,8
CVSS
HIGH
XML External Entity Injection
611
CWE
Product Name: BIG-IP
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
F5 Networks BIG-IP XML External Entity Injection Vulnerability
Attackers can exploit this issue to obtain potentially sensitive information from local files on computers running the vulnerable application and to carry out other attacks. An attacker can send a specially crafted POST request to the vulnerable application, which will include an XML document containing an external entity declaration. This will cause the application to return the content of the specified file.
Mitigation:
Users should apply the appropriate updates to vulnerable installations. Additionally, users should ensure that the application is not exposed to untrusted networks.