Last Modified: Feb 03, 2026
Affected Product(s):
BIG-IP ASM
Known Affected Versions:
17.5.0, 17.5.1, 17.5.1.2, 17.5.1.3, 17.5.1.4
Opened: May 02, 2024 Severity: 3-Major
The pure wildcard cookie configuration "Insert Secure Attribute" is disabled and "Insert SameSite Attribute" is not set to "Lax".
The configuration is incorrect.
Creating the policy using the policy templates.
Configure it manually: Enable "Insert Secure Attribute" and set "Insert SameSite Attribute" to "Lax".
None