Last Modified: Aug 23, 2019
See more info
BIG-IP Install/Upgrade, TMOS
Known Affected Versions:
14.1.0, 18.104.22.168, 22.214.171.124, 126.96.36.199, 188.8.131.52, 184.108.40.206, 220.127.116.11, 15.0.0, 15.0.1
Opened: Mar 20, 2019
When multiple attributes in a list match multiple roles, the wrong role may be assigned. Alternatively, authentication may fail when check-roles-group is disabled.
BIG-IP assigns the user to the last attribute in the list that matches a role yielding more restrictive set of permissions. Authentication may fail when check-roles-group is disabled.
LDAP server replies with a list of attributes (e.g., list of memberOf) where more than one match existing role.