Filtered by vendor F5 Subscriptions
Filtered by product Big-iq Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-47139 1 F5 2 Big-iq, Big-iq Centralized Management 2025-08-06 6.8 Medium
A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the Administrator role to run JavaScript in the context of the currently logged-in user.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2014-3220 1 F5 1 Big-iq 2025-04-12 N/A
F5 BIG-IQ Cloud and Security 4.0.0 through 4.1.0 allows remote authenticated users to change the password of arbitrary users via the name parameter in a request to the user's page in mgmt/shared/authz/users/.