Bug ID 564039: WebSafe "Missing component" check gets applied on request with different referrer domain.

Last Modified: Jul 18, 2026

Affected Product(s):
BIG-IP FPS(all modules)

Known Affected Versions:
11.6.0, 11.6.0 hf1, 11.6.0 hf2, 11.6.0 hf3, 11.6.0 hf4, 11.6.0 hf5, 11.6.0 hf6, 11.6.0 hf7, 11.6.0 hf8, 12.0.0, 12.0.0 hf1, 12.0.0 hf2, 12.0.0 hf3, 12.0.0 hf4

Fixed In:
12.1.0, 11.6.1

Opened: Dec 20, 2015

Severity: 2-Critical

Symptoms

The "Missing component" checker looks only looks at referrer header path and not the domain name. The result is a false positive alert indicating the cookie is missing.

Impact

False positive missing component alerts when redirecting from other sites to a WebSafe protected site.

Conditions

The referrer is coming from a different domain and the system is still performing component validation check.

Workaround

Do not configure the same URL as a protected page.

Fix Information

The Missing Component check now looks at the referrer header path as well as the domain name. This prevents false-positive Missing Component alerts when redirecting from other sites to a WebSafe protected site.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips