CVE-2019-8331: F5 BIG-IP Access Policy Manager
Medium severity, CVSS 6.1. EPSS: 16.4% chance of exploitation in the next 30 days.
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
Affected products
- F5 BIG-IP Access Policy Manager: from 12.1.0, before 12.1.5.1 (fixed in 12.1.5.1); from 13.0.0, before 13.1.3.4 (fixed in 13.1.3.4); from 14.0.0, before 14.1.2.5 (fixed in 14.1.2.5); from 15.0.0, before 15.1.0 (fixed in 15.1.0)
- F5 BIG-IP Advanced Firewall Manager: from 12.1.0, before 12.1.5.1 (fixed in 12.1.5.1); from 13.0.0, before 13.1.3.4 (fixed in 13.1.3.4); from 14.0.0, before 14.1.2.5 (fixed in 14.1.2.5); from 15.0.0, before 15.1.0 (fixed in 15.1.0)
- F5 BIG-IP Analytics: from 12.1.0, before 12.1.5.1 (fixed in 12.1.5.1); from 13.0.0, before 13.1.3.4 (fixed in 13.1.3.4); from 14.0.0, before 14.1.2.5 (fixed in 14.1.2.5); from 15.0.0, before 15.1.0 (fixed in 15.1.0)
- F5 BIG-IP Application Acceleration Manager: from 12.1.0, before 12.1.5.1 (fixed in 12.1.5.1); from 13.0.0, before 13.1.3.4 (fixed in 13.1.3.4); from 14.0.0, before 14.1.2.5 (fixed in 14.1.2.5); from 15.0.0, before 15.1.0 (fixed in 15.1.0)
- F5 BIG-IP Application Security Manager: from 12.1.0, before 12.1.5.1 (fixed in 12.1.5.1); from 13.0.0, before 13.1.3.4 (fixed in 13.1.3.4); from 14.0.0, before 14.1.2.5 (fixed in 14.1.2.5); from 15.0.0, before 15.1.0 (fixed in 15.1.0)
- F5 BIG-IP Domain Name System: from 12.1.0, before 12.1.5.1 (fixed in 12.1.5.1); from 13.0.0, before 13.1.3.4 (fixed in 13.1.3.4); from 14.0.0, before 14.1.2.5 (fixed in 14.1.2.5); from 15.0.0, before 15.1.0 (fixed in 15.1.0)
- F5 BIG-IP Edge Gateway: from 12.1.0, before 12.1.5.1 (fixed in 12.1.5.1); from 13.0.0, before 13.1.3.4 (fixed in 13.1.3.4); from 14.0.0, before 14.1.2.5 (fixed in 14.1.2.5); from 15.0.0, before 15.1.0 (fixed in 15.1.0)
- F5 BIG-IP Fraud Protection Service: from 12.1.0, before 12.1.5.1 (fixed in 12.1.5.1); from 13.0.0, before 13.1.3.4 (fixed in 13.1.3.4); from 14.0.0, before 14.1.2.5 (fixed in 14.1.2.5); from 15.0.0, before 15.1.0 (fixed in 15.1.0)
- F5 BIG-IP Global Traffic Manager: from 12.1.0, before 12.1.5.1 (fixed in 12.1.5.1); from 13.0.0, before 13.1.3.4 (fixed in 13.1.3.4); from 14.0.0, before 14.1.2.5 (fixed in 14.1.2.5); from 15.0.0, before 15.1.0 (fixed in 15.1.0)
- F5 BIG-IP Link Controller: from 12.1.0, before 12.1.5.1 (fixed in 12.1.5.1); from 13.0.0, before 13.1.3.4 (fixed in 13.1.3.4); from 14.0.0, before 14.1.2.5 (fixed in 14.1.2.5); from 15.0.0, before 15.1.0 (fixed in 15.1.0)
- F5 BIG-IP Local Traffic Manager: from 12.1.0, before 12.1.5.1 (fixed in 12.1.5.1); from 13.0.0, before 13.1.3.4 (fixed in 13.1.3.4); from 14.0.0, before 14.1.2.5 (fixed in 14.1.2.5); from 15.0.0, before 15.1.0 (fixed in 15.1.0)
- F5 BIG-IP Policy Enforcement Manager: from 12.1.0, before 12.1.5.1 (fixed in 12.1.5.1); from 13.0.0, before 13.1.3.4 (fixed in 13.1.3.4); from 14.0.0, before 14.1.2.5 (fixed in 14.1.2.5); from 15.0.0, before 15.1.0 (fixed in 15.1.0)
- F5 BIG-IP Webaccelerator: from 12.1.0, before 12.1.5.1 (fixed in 12.1.5.1); from 13.0.0, before 13.1.3.4 (fixed in 13.1.3.4); from 14.0.0, before 14.1.2.5 (fixed in 14.1.2.5); from 15.0.0, before 15.1.0 (fixed in 15.1.0)
- Getbootstrap Bootstrap: before 3.4.1 (fixed in 3.4.1); from 4.3.0, before 4.3.1 (fixed in 4.3.1)
- Red Hat Virtualization Manager: version 4.3 only
- Tenable Tenable.sc: before 5.19.0 (fixed in 5.19.0)
Published 2019-02-20. Last modified 2026-06-17.