K11342432 : BIG-IP HTTP non-RFC-compliant security exposure
Discription

Security Advisory Description This issue occurs when a non-RFC-compliant HTTP request is received by a virtual server on a system matching one of the following conditions: BIG-IP 15.1.0 and later version with a virtual server with an HTTP profile with Enforce RFC Compliance enabled. All supported versions of BIG-IP with a virtual server with an ASM/Advanced WAF security policy. Impact Non-RFC-compliant HTTP requests are forwarded to the backend pool members. Symptoms As a result of this issue, you may encounter the following symptom: The backend pool member may respond with a 400 Bad Request HTTP…Read More

Back to Main

Subscribe for the latest news: