CVE-2019-6626: F5 BIG-IP Advanced Firewall Manager
Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.
On BIG-IP (AFM, Analytics, ASM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.3.4, A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traffic Management User Interface (TMUI), also known as the Configuration utility.
Affected products
- F5 BIG-IP Advanced Firewall Manager: from 11.5.1, up to and including 11.6.3; from 12.1.0, before 12.1.4.1 (fixed in 12.1.4.1); from 13.0.0, before 13.1.1.5 (fixed in 13.1.1.5); from 14.0.0, before 14.0.0.5 (fixed in 14.0.0.5); from 14.1.0, before 14.1.0.6 (fixed in 14.1.0.6)
- F5 BIG-IP Analytics: from 11.5.1, up to and including 11.6.3; from 12.1.0, before 12.1.4.1 (fixed in 12.1.4.1); from 13.0.0, before 13.1.1.5 (fixed in 13.1.1.5); from 14.0.0, before 14.0.0.5 (fixed in 14.0.0.5); from 14.1.0, before 14.1.0.6 (fixed in 14.1.0.6)
- F5 BIG-IP Application Security Manager: from 11.5.1, up to and including 11.6.3; from 12.1.0, before 12.1.4.1 (fixed in 12.1.4.1); from 13.0.0, before 13.1.1.5 (fixed in 13.1.1.5); from 14.0.0, before 14.0.0.5 (fixed in 14.0.0.5); from 14.1.0, before 14.1.0.6 (fixed in 14.1.0.6)
Published 2019-07-03. Last modified 2026-06-17.