Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
On BIG-IP Advanced WAF and ASM version 15.1.x before 15.1.0.2, 15.0.x before 15.0.1.4, 14.1.x before 14.1.2.5, 13.1.x before 13.1.3.4, 12.1.x before 12.1.5.2, and 11.6.x before 11.6.5.2, when receiving a unauthenticated client request with a maliciously crafted URI, a BIG-IP Advanced WAF or ASM virtual server configured with a DoS profile with Proactive Bot Defense (versions prior to 14.1.0), or a Bot Defense profile (versions 14.1.0 and later), may subject clients and web servers to Open Redirection attacks. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
F5 BIG-IP ASM 输入验证错误漏洞
Vulnerability Description
F5 BIG-IP ASM是美国F5公司的一款Web应用程序防火墙(WAF),它提供安全的远程接入、保护电子邮件、简化Web接入控制,同时增强网络和应用性能。 BIG-IP ASM 存在输入验证错误漏洞,该漏洞源于可能会受到客户端和web服务器打开重定向攻击。以下产品及版本受到影响:BIG-IP Advanced WAF and ASM version 15.1.x before 15.1.0.2, 15.0.x before 15.0.1.4, 14.1.x before 14.1.2.5, 13.1.
CVSS Information
N/A
Vulnerability Type
N/A