Bug ID 1132409: Legal OpenAPI3 matrix type requests are blocked or alarmed in Bot Defense

Last Modified: Apr 28, 2025

Affected Product(s):
BIG-IP ASM(all modules)

Fixed In:
17.1.0

Opened: Jul 27, 2022

Severity: 2-Critical

Symptoms

When requests with matrix path parameters are sent to BIG-IP, then they can be incorrectly blocked or alarmed with Illegal parameter value violation.

Impact

Legal requests are recognized as violation.

Conditions

- OpenAPI ASM security policy is in enabled. - Illegal parameter value violation is set to enabled. - Request has matrix path parameters.

Workaround

None

Fix Information

Updated naming style of path parameters.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips