Last Modified: May 29, 2024
Affected Product(s):
BIG-IP APM
Known Affected Versions:
17.0.0.1
Fixed In:
17.1.0, 17.0.0.2, 16.1.3.3, 15.1.8.1, 14.1.5.3
Opened: Oct 17, 2022 Severity: 3-Major
In muti-domain Single Sign-On (SSO) or SAML Auth, the location header query string separator is converted from "?" to "%3F" or / to "%2F"
MultiDomain Auth or SAML Auth will fail
- Create an access policy with a redirect to login page.
None
A function that was used to normalize URLs was corrected.