CVE-2020-5889: F5 BIG-IP Access Policy Manager

Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.

On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, in BIG-IP APM portal access, a specially crafted HTTP request can lead to reflected XSS after the BIG-IP APM system rewrites the HTTP response from the untrusted backend server and sends it to the client.

Affected products

  • F5 BIG-IP Access Policy Manager: from 14.1.0, up to and including 14.1.2.3; from 15.0.0, up to and including 15.0.1.2; from 15.1.0, up to and including 15.1.0.1

Published 2020-04-30. Last modified 2026-06-17.