CVE-2024-47139: F5 BIG-IQ Centralized Management

Medium severity, CVSS 6.8. EPSS: 0.6% chance of exploitation in the next 30 days.

A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the Administrator role to run JavaScript in the context of the currently logged-in user.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected products

  • F5 BIG-IQ Centralized Management: version 8.2.0 only

Published 2024-10-16. Last modified 2026-06-17.