QID 376188

Date Published: 2021-12-27

QID 376188: F5 BIG-IP Local Traffic Manager (LTM), Application Security Manager (ASM), Access Policy Manager (APM) Apache HTTPD Vulnerability (K25126370)

In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL.CVE-2019-10098

Vulnerable Component: BIG-IP LTM,ASM,APM

Affected Versions:
16.0.0 - 16.1.2
15.0.0 - 15.1.4
14.0.0 - 14.1.4

QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.

An attacker can abuse this vulnerability in a phishing attack or as part of a client-side attack on browsers.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    The vendor has released patch, for more information please visit: K25126370
    Vendor References

    CVEs related to QID 376188

    Software Advisories
    Advisory ID Software Component Link
    K25126370 URL Logo support.f5.com/csp/article/K25126370