Bug ID 542817: Specific numbers that are not credit card numbers are being masked as such

Last Modified: Sep 13, 2023

Affected Product(s):
BIG-IP ASM(all modules)

Known Affected Versions:
10.2.4, 11.5.2, 11.5.3, 11.5.4, 11.5.5, 11.5.6, 11.5.7, 11.5.8, 11.5.9, 11.5.10, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.6.3.1, 11.6.3.2, 11.6.3.3, 11.6.3.4, 11.6.4, 11.6.5, 11.6.5.1, 11.6.5.2, 11.6.5.3, 12.0.0, 12.0.0 HF1, 12.1.0 HF1, 12.0.0 HF2, 12.1.0 HF2, 12.0.0 HF3, 12.0.0 HF4, 12.1.1 HF1, 12.1.1 HF2, 12.1.2 HF1, 12.1.2 HF2, 12.1.0, 12.1.1, 12.1.2, 12.1.3, 12.1.3.1, 12.1.3.2, 12.1.3.3, 12.1.3.4, 12.1.3.5, 12.1.3.6, 12.1.3.7

Fixed In:
13.0.0, 12.1.4

Opened: Sep 01, 2015

Severity: 4-Minor

Related Article: K11619228

Symptoms

ASM blocks or masks when a specific credit card number range with specific length appears in the response.

Impact

The traffic passes masked or blocked to the end client.

Conditions

The Data Guard feature is turned on and set to Block, Alarm or Mask. The responses contains credit card numbers with specific ranges.

Workaround

a partial workaround is to turn off the Data Guard feature, then none of the credit cards numbers will be masked nor blocked.

Fix Information

The system now correctly masks and/or blocks only relevant credit cards, specifically not masking credit card numbers starting with specific number that are in a length range.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips