Last Modified: Nov 07, 2022
Affected Product(s):
BIG-IQ Web App Security (ASM)
Known Affected Versions:
5.0.0, 5.0.0 HF1, 5.1.0, 5.2.0, 5.4.0, 5.4.0 HF1, 5.4.0 HF2, 6.0.1, 6.0.1.1, 6.0.1.2, 6.1.0
Fixed In:
7.0.0
Opened: Jun 04, 2019 Severity: 4-Minor
User-defined ASM signature ids can be different on BIG-IQ virtual server BIG-IP and cause information on event logs to be wrong or missing.
User-defined ASM signature information on event logs wrong or missing
Have two BIG-IP devices and a different user-defined ASM signature on each. Discover & import both devices to BIG-IQ. On BIG-IQ, one signature (the first) got signatureId that match the BIG-IP (30000000) but the second one will have signatureId that ends with '1' because signatureId is unique. When an event that triggered by the second user-defined signature is logged to BIG-IQ, BIG-IQ will show the signature by its signature id which is a different signature on BIG-IQ.
None
None