Last Modified: May 29, 2024
Affected Product(s):
BIG-IP ASM
Known Affected Versions:
14.1.0, 14.1.0.1
Fixed In:
15.0.0, 14.1.0.2
Opened: Sep 05, 2018 Severity: 3-Major
Bot defense blocks a request containing a TSPD101 cookie in query string. TSPD101 is sent when using the Safari browser, and cross-site redirect protection is applied on a request.
Cross-site requests are blocked during the grace period configured on the bot defense profile.
- ASM provisioned. - Bot Defense profile attached to a virtual server. - Cross-site redirection is applied on a request. - Using the Safari browser.
Disable browser verification in the bot defense profile.
Cross-site redirect protection now works as expected when cookie is sent via query string.