QID 377670
QID 377670: F5 BIG-IP Application Security Manager (ASM) Big-ip advanced waf, asm, and nginx app protect Web Application Firewall (WAF) xml encoding security exposure (K49237345)
Vulnerable Component: BIG-IP ASM
Affected Versions:
16.1.0 - 16.1.2
15.1.0 - 15.1.5
14.1.0 - 14.1.4
13.1.0 - 13.1.4
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
The attack signature check fails to detect and block such requests, as expected of a security policy.
Solution
For more information about patch details please refer to K49237345
Vendor References
- K49237345 -
support.f5.com/csp/article/K49237345
CVEs related to QID 377670
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K49237345 |
|