CVE-2020-5889: F5 BIG-IP Access Policy Manager
Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.
On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, in BIG-IP APM portal access, a specially crafted HTTP request can lead to reflected XSS after the BIG-IP APM system rewrites the HTTP response from the untrusted backend server and sends it to the client.
Affected products
- F5 BIG-IP Access Policy Manager: from 14.1.0, up to and including 14.1.2.3; from 15.0.0, up to and including 15.0.1.2; from 15.1.0, up to and including 15.1.0.1
Published 2020-04-30. Last modified 2026-06-17.