CVE-2019-6639: F5 BIG-IP Advanced Firewall Manager

Medium severity, CVSS 4.8. EPSS: 0.7% chance of exploitation in the next 30 days.

On BIG-IP (AFM, PEM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.1-11.5.8, an undisclosed TMUI pages for AFM and PEM Subscriber management are vulnerable to a stored cross-site scripting (XSS) issue. This is a control plane issue only and is not accessible from the data plane. The attack requires a malicious resource administrator to store the XSS.

Affected products

  • F5 BIG-IP Advanced Firewall Manager: from 11.5.0, before 11.5.9 (fixed in 11.5.9); from 11.6.0, before 11.6.4 (fixed in 11.6.4); from 12.1.0, before 12.1.4.1 (fixed in 12.1.4.1); from 13.0.0, before 13.1.1.5 (fixed in 13.1.1.5); from 14.0.0, before 14.0.0.5 (fixed in 14.0.0.5); from 14.1.0, before 14.1.0.6 (fixed in 14.1.0.6)
  • F5 BIG-IP Policy Enforcement Manager: from 11.5.0, before 11.5.9 (fixed in 11.5.9); from 11.6.0, before 11.6.4 (fixed in 11.6.4); from 12.1.0, before 12.1.4.1 (fixed in 12.1.4.1); from 13.0.0, before 13.1.1.5 (fixed in 13.1.1.5); from 14.0.0, before 14.0.0.5 (fixed in 14.0.0.5); from 14.1.0, before 14.1.0.6 (fixed in 14.1.0.6)

Published 2019-07-03. Last modified 2026-06-17.