Bug ID 896689: Asynchronous tasks can be managed via unintended endpoints

Last Modified: May 27, 2020

Bug Tracker

Affected Product:  See more info
BIG-IP TMOS(all modules)

Known Affected Versions:
13.1.0, 13.1.0.1, 13.1.0.2, 13.1.0.3, 13.1.0.4, 13.1.0.5, 13.1.0.6, 13.1.0.7, 13.1.0.8, 13.1.1, 13.1.1.1, 13.1.1.2, 13.1.1.3, 13.1.1.4, 13.1.1.5, 13.1.3, 13.1.3.1, 13.1.3.2, 13.1.3.3, 14.1.0, 14.1.0.1, 14.1.0.2, 14.1.0.3, 14.1.0.4, 14.1.0.5, 14.1.0.6, 14.1.2, 14.1.2.1, 14.1.2.2, 14.1.2.3, 14.1.2.4, 14.1.2.5, 15.1.0, 15.1.0.1, 15.1.0.2, 15.1.0.3

Opened: Apr 07, 2020
Severity: 4-Minor

Symptoms

An asynchronous task created on one endpoint can be started using some other endpoint

Impact

The asynchronous task can be started using this endpoint but this is not intended behavior.

Conditions

Create an asynchronous task e.g. creating qkview using ihealth using endpoint /mgmt/tm/task/util/ihealth Gather the task id of the created asynchronous task and send it to a different endpoint e.g. /mgmt/tm/task/cli/script

Workaround

None

Fix Information

None

Behavior Change