QID 376188
Date Published: 2021-12-27
QID 376188: F5 BIG-IP Local Traffic Manager (LTM), Application Security Manager (ASM), Access Policy Manager (APM) Apache HTTPD Vulnerability (K25126370)
In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL.CVE-2019-10098
Vulnerable Component: BIG-IP LTM,ASM,APM
Affected Versions:
16.0.0 - 16.1.2
15.0.0 - 15.1.4
14.0.0 - 14.1.4
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
An attacker can abuse this vulnerability in a phishing attack or as part of a client-side attack on browsers.
Solution
The vendor has released patch, for more information please visit: K25126370
Vendor References
- K25126370 -
support.f5.com/csp/article/K25126370
CVEs related to QID 376188
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K25126370 |
|