AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-38138

HIGH · CVSS 7.5 EPSS 0.39%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-08-02 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2023-38138
Severity
HIGH
CVSS
7.5
EPSS
0.39%
Java BIG-IP

Original NVD Description

A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.