Bug ID 751710: False positive cookie hijacking violation

Last Modified: May 29, 2024

Affected Product(s):
BIG-IP ASM(all modules)

Fixed In:
15.0.0, 14.1.2.1, 14.0.0.5, 13.1.1.5

Opened: Dec 03, 2018

Severity: 3-Major

Symptoms

A false positive cookie hijacking violation.

Impact

False positive violation / blocking.

Conditions

-- Several sites are configured on the policy, without subdomain. -- TS cookies are sent with the higher domain level then the configured. -- A single cookie from another host (that belongs to the same policy) arrives and is mistaken as the other site cookie.

Workaround

N/A

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips