Bug ID 756932: iRule command 'ACCESS::session data get -secure' can fail when evaluating empty variables

Last Modified: Sep 14, 2023

Affected Product(s):
BIG-IP APM(all modules)

Known Affected Versions:
13.1.0,,,,,,,,, 13.1.1,,,,, 13.1.3,,,,,,, 13.1.4,, 13.1.5,, 14.0.0,,,,,, 14.0.1,, 14.1.0,,,,,, 14.1.2,,,,,,,,, 14.1.3,, 14.1.4,,,,,,, 14.1.5,,,,,, 15.0.0, 15.0.1,,,,

Fixed In:

Opened: Jan 29, 2019

Severity: 3-Major


Use of the iRule command 'ACCESS::session data get -secure <empty variable>' might fail intermittently, which might result in BIG-IP traffic processing failures and a Tcl error logged in /var/log/ltm: err tmm2[22011]: 01220001:3: TCL error: /Common/sp_irule <HTTP_REQUEST> - variable lookup failed (line 1)Illegal argument (line 1) (line 1) invoked from within "ACCESS::session data get -secure "session.saml.last.attr.name.foo"".


Connection drop.


Use of -secure flag to get data from an empty variable from ACCESS::session inside iRules.


Use an iRule catch statement.

Fix Information

The system now checks for empty variable value before attempting decryption.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips