Bug ID 2339781: [APM] SAML authentication fails when the SAML attribute FriendlyName contains a valid single quote (').

Last Modified: Jul 28, 2026

Affected Product(s):
BIG-IP None(all modules)

Known Affected Versions:
17.1.3.2, 17.1.3.4, 21.0.0.2, 21.0.0.3

Opened: Jun 17, 2026

Severity: 3-Major

Symptoms

After upgrading BIG-IP APM from version 17.5.1.3 to 17.5.1.6, SAML authentication fails when the SAML Identity Provider (IdP) includes a single-quote character (', hex 0x27) in the FriendlyName attribute of a SAML assertion. This causes the session variable write to fail, leading to authentication rejection and session termination.

Impact

SAML authentication is rejected, blocking user access.

Conditions

SAML authentication is configured with BIG-IP as the Service Provider (SP). The IdP sends SAML assertions where the FriendlyName contains a single quote (e.g., User's Object ID). The issue is reproducible when a single quote is present in the FriendlyName attribute.

Workaround

Remove the single-quote character from the FriendlyName configuration on the IdP.

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips