Last Modified: Apr 28, 2025
Affected Product(s):
BIG-IP ASM
Known Affected Versions:
12.1.1, 12.1.1 HF1, 12.1.1 HF2, 12.1.2, 12.1.2 HF1, 12.1.2 HF2, 12.1.3, 12.1.3.1, 12.1.3.2, 12.1.3.3, 12.1.3.4, 12.1.3.5, 12.1.3.6, 12.1.3.7, 12.1.4, 12.1.4.1, 12.1.5, 12.1.5.1, 12.1.5.2, 12.1.5.3, 12.1.6, 13.0.0, 13.0.0 HF1, 13.0.0 HF2, 13.0.0 HF3, 13.0.1
Fixed In:
13.1.0
Opened: Jun 15, 2016 Severity: 3-Major
ASM cannot extract IPv6 addresses from XFF header when it is encapsulated within square brackets.
ASM treats the TCP connection IP address as the request IP address instead of the one present in the XFF header.
1. Trust XFF is on in ASM policy. 2. IP address in XFF header is IPv6 and encapsulated within square brackets.
None.
ASM parser now allows IPV6 to be encapsulated within square brackets.