Bug ID 517019: AVR-HTTP (and Application DoS): Detection of pool-member is sometimes incorrect

Last Modified: Sep 13, 2023

Affected Product(s):
BIG-IP ASM, AVR(all modules)

Known Affected Versions:
11.5.1 HF1, 11.5.1 HF2, 11.5.1 HF3, 11.5.1 HF4, 11.5.1 HF5, 11.5.1 HF6, 11.5.1 HF7, 11.5.1 HF8, 11.5.1 HF9, 11.5.1 HF10, 11.5.1 HF11, 11.5.2 HF1, 11.5.3 HF1, 11.5.3 HF2, 11.5.4 HF1, 11.5.4 HF2, 11.5.4 HF3, 11.5.4 HF4, 12.1.0 HF1, 12.1.0 HF2, 12.1.1 HF1, 12.1.1 HF2, 12.1.2 HF1, 12.1.2 HF2

Fixed In:
12.0.0, 11.6.0 HF5

Opened: Apr 08, 2015

Severity: 2-Critical

Symptoms

AVR sometimes detects the incorrect BIG-IP module that created a response to an HTTP transaction.

Impact

1. AVR report an incorrect module. 2. Application DoS is using this information for its decisions, and thus can choose a mitigation action that is different from the desired one.

Conditions

Using AVR HTTP profile or Application DoS, and having a transaction that was responded to by a BIG-IP modules, such as DoS, Cache, iRules, and so on.

Workaround

None.

Fix Information

The detection of the internal module is done correctly, so that the correct mitigation action is chosen.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips