Last Modified: May 29, 2024
Affected Product(s):
BIG-IP ASM
Known Affected Versions:
15.1.4, 15.1.4.1, 15.1.5, 15.1.5.1, 15.1.6
Fixed In:
17.0.0, 16.1.2.2, 15.1.6.1
Opened: Dec 26, 2021 Severity: 3-Major
On OWASP dashboard, both 2021 and 2017, the Disallow DTDs in XML content profile protection is not calculated correctly on the xml-profile allowDTD field.
Actual OWASP compliance for this protection can be different from the one shown by the GUI.
Open the OWASP page for any non-parent/child security policy, (Security ›› Overview : OWASP Compliance). For OWASP 2017, DTDs is located under A4 category, and for 2021 under A5 category.
The actual conditions that satisfy the Disallow DTDs in XML content profile protection are: 1. 'XML data does not comply with format settings' violation should be set to alarm+block. 2. 'Malformed XML data' violation should be set to alarm + block. 3. No XML content profile in the policy is set so that allowDTDs to true.
Scoring calculation was changed: Now score will be given only if no XML content profile in the policy has allowDTDs field set as true.