QID 376076

Date Published: 2021-11-18

QID 376076: F5 BIG-IP Application Security Manager (ASM), Local Traffic Manager (LTM), Access Policy Manager (APM) Apache Tomcat Vulnerability (K32469285)

Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.CVE-2021-33037

Vulnerable Component: BIG-IP ASM,LTM,APM

Affected Versions:
16.0.0 - 16.1.0
15.1.0 - 15.1.3
14.1.0 - 14.1.4
13.1.0 - 13.1.4
12.1.0 - 12.1.6
11.6.1 - 11.6.5

QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.

A remote attacker may be able to bypass security controls and gain access to restricted content, such as a site administration page.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vendor has released patch, for more information please visit: K32469285
    Vendor References

    CVEs related to QID 376076

    Software Advisories
    Advisory ID Software Component Link
    K32469285 URL Logo support.f5.com/csp/article/K32469285