Bug ID 864321: Default Apache testing page is reachable at <mgmt-ip>/noindex

Last Modified: Jan 20, 2023

Bug Tracker

Affected Product:  See more info
BIG-IP TMOS(all modules)

Known Affected Versions:
14.1.0, 14.1.0.1, 14.1.0.2, 14.1.0.3, 14.1.0.5, 14.1.0.6, 14.1.2, 14.1.2.1, 14.1.2.2, 14.1.2.3, 14.1.2.4, 14.1.2.5, 14.1.2.6, 14.1.2.7, 14.1.2.8, 14.1.3, 14.1.3.1, 14.1.4, 14.1.4.1, 14.1.4.2, 14.1.4.3, 14.1.4.4, 14.1.4.5, 14.1.4.6, 14.1.5, 14.1.5.1, 14.1.5.2, 14.1.5.3

Fixed In:
16.0.0

Opened: Dec 20, 2019
Severity: 3-Major

Symptoms

For BIG-IP v14.1.x and later, the default testing page of the Apache web-server is accessible at <mgmt-ip>/noindex.

Impact

Limited information about the Apache web server and its operating system is available to users with access to the mgmt port interface.

Conditions

This is encountered when navigating to the /noindex page from the web browser.

Workaround

None.

Fix Information

/noindex now returns a 403 Forbidden Error Response.

Behavior Change