Last Modified: Sep 20, 2024
Affected Product(s):
BIG-IP ASM
Known Affected Versions:
16.0.0, 16.0.0.1, 16.0.1, 16.0.1.1, 16.0.1.2, 16.1.0, 16.1.1, 16.1.2
Fixed In:
16.1.2.1
Opened: Aug 27, 2021 Severity: 3-Major
SSRF Violation is shown as a URL Entity Reference instead of a Parameter Entity Reference.
Wrong Entity Reference in the SSRF violation is misleading.
- Create a URI data type parameter - Add a host to the SSRF Host List - Send traffic which contains the URI parameter with the value configured in the SSRF Host List
N/A
Corrected the Entity reference as a parameter instead of a URL in the SSRF violation.