Last Modified: May 29, 2024
Affected Product(s):
BIG-IP ASM
Known Affected Versions:
15.1.4, 15.1.4.1, 15.1.5, 15.1.5.1, 15.1.6, 15.1.6.1, 15.1.7, 15.1.8, 15.1.8.1, 15.1.8.2
Fixed In:
15.1.9
Opened: Mar 22, 2022 Severity: 3-Major
When the BIG-IP system receives crafted/malformed requests to fictive /TSbd URLs, the BIG-IP system behaves in three different ways: -- Displaying a default response page with Support ID -- Reset the connection -- Displaying an alternative response page, e.g. 'Leaked Credentials Detected' OR 'Login Failed').
Inconsistent behavior for malformed /TSbd fictive URLs.
Use malformed /TSbd URLs.
None
None