Bug ID 854001: TMM might crash in case of trusted bot signature and API protected url

Last Modified: Sep 13, 2023

Affected Product(s):
BIG-IP ASM(all modules)

Known Affected Versions:
14.1.0, 14.1.0.1, 14.1.0.2, 14.1.0.3, 14.1.0.5, 14.1.0.6, 14.1.2, 14.1.2.1, 14.1.2.2, 14.1.2.3, 14.1.2.4, 14.1.2.5, 14.1.2.6, 14.1.2.7, 14.1.2.8, 14.1.3, 14.1.3.1, 14.1.4, 14.1.4.1, 15.0.0, 15.0.1, 15.0.1.1, 15.0.1.2, 15.0.1.3, 15.0.1.4, 15.1.0, 15.1.0.1, 15.1.0.2, 15.1.0.3, 15.1.0.4, 15.1.0.5, 15.1.1, 15.1.2, 15.1.2.1, 15.1.3, 15.1.3.1, 16.0.0, 16.0.0.1, 16.0.1, 16.0.1.1

Fixed In:
16.1.0, 16.0.1.2, 15.1.4, 14.1.4.2

Opened: Nov 28, 2019

Severity: 2-Critical

Symptoms

When sending request to a protected API URL, with a trusted bot signature, tmm tries to perform reverse DNS to verify the signature. During this process, the URL qualification might change. In this case - tmm crashes.

Impact

Traffic disrupted while tmm restarts.

Conditions

-- Bot Defense profile attached. -- 'API Access for Browsers and Mobile Applications' is enabled. -- A DNS server is configured. -- Request is sent to an API-qualified URL. -- Request is sent with a trusted bot signature.

Workaround

Disable the 'API Access for Browsers and Mobile Applications' or remove the DNS server.

Fix Information

An issue where tmm could crash when processing a request sent to a protected API URL with a trusted bot signature has been fixed.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips