Last Modified: Jul 28, 2026
Affected Product(s):
BIG-IP (all modules)
Known Affected Versions:
17.1.3.2, 17.1.3.4, 21.0.0.2, 21.0.0.3
Opened: Jun 17, 2026 Severity: 3-Major
After upgrading BIG-IP APM from version 17.5.1.3 to 17.5.1.6, SAML authentication fails when the SAML Identity Provider (IdP) includes a single-quote character (', hex 0x27) in the FriendlyName attribute of a SAML assertion. This causes the session variable write to fail, leading to authentication rejection and session termination.
SAML authentication is rejected, blocking user access.
SAML authentication is configured with BIG-IP as the Service Provider (SP). The IdP sends SAML assertions where the FriendlyName contains a single quote (e.g., User's Object ID). The issue is reproducible when a single quote is present in the FriendlyName attribute.
Remove the single-quote character from the FriendlyName configuration on the IdP.
None