Bug ID 588087: Attack prevention isn't escalating under some conditions in session opening mitigation

Last Modified: Apr 28, 2025

Affected Product(s):
BIG-IP ASM(all modules)

Known Affected Versions:
12.1.0, 12.1.0 HF1, 12.1.0 HF2, 12.1.1, 12.1.1 HF1, 12.1.1 HF2

Fixed In:
13.0.0, 12.1.2

Opened: Apr 18, 2016

Severity: 3-Major

Symptoms

Attack is detected and isn't escalating in session opening

Impact

The attack continues.

Conditions

A session opening attack, challenges are being answered by the attacker.

Workaround

Configure the attack prevention as rate limit.

Fix Information

Fixed attack escalation in some cases on session opening.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips