Last Modified: Oct 19, 2025
Affected Product(s):
BIG-IP ASM
Known Affected Versions:
15.1.4, 15.1.4.1, 15.1.5, 15.1.5.1, 15.1.6, 15.1.6.1, 15.1.7, 15.1.8, 15.1.8.1, 15.1.8.2, 15.1.9, 15.1.9.1, 15.1.10, 15.1.10.2, 15.1.10.3, 15.1.10.4, 15.1.10.5, 15.1.10.6, 15.1.10.7, 15.1.10.8
Opened: Feb 01, 2022 Severity: 4-Minor
If an incoming JSON profile contains an XML parameter, and its type value type is defined as "XML value", the XML parser will parse the parameter value and upon seeing the \ escape character, XML parser validation raises a "Malformed XML data" violation.
False positive malformed XML violation.
-- Wildcard URL with default JSON content profile applied to a JSON content-type. -- A parameter name XML with parameter value type defined as "XML value". -- XML value contains an escape (\") character in the XML body.
N/A
None