Last Modified: Nov 14, 2024
Affected Product(s):
BIG-IP ASM
Opened: Aug 08, 2023 Severity: 3-Major
When "Allow Repeated Occurrences" is disabled on Cookie header and Illegal Repeated Header violation is enabled in Learning and Blocking settings, the expectation is that any request with multiple Cookie headers will be flagged as alarm/block. However, this does not happen.
Illegal requests are allowed.
1) "Allow Repeated Occurrences" is disabled on Cookie header via Rest. 2) Illegal Repeated Header violation is enabled in Learning and Blocking settings.
N/A
None