Last Modified: Nov 14, 2024
Affected Product(s):
BIG-IP ASM
Known Affected Versions:
15.1.4, 15.1.4.1, 15.1.5
Fixed In:
17.0.0, 16.1.2.2, 15.1.5.1, 14.1.4.6, 13.1.5
Opened: Aug 05, 2021 Severity: 4-Minor
When internal parameter for "authorization header decode failure" is disabled, Valid NTLM type-1 message will be blocked with "Unparsable request content" violation.
Valid NTLM Type-1 message will be blocked by ASM.
Disable internal parameter ignore_authorization_header_decode_failure
Enable internal parameter ignore_authorization_header_decode_failure, ASM will not block the NTLM type-1 message request
None