When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to a virtual server, undisclosed requests can cause the BD process to terminate. The condition results from setting the Request Body Handling option in the Header-Based Content Profile for an Allowed URL with "Apply value and content signatures and detect threat campaigns." Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
References
| Link | Resource |
|---|---|
| https://my.f5.com/manage/s/article/K000137416 | Vendor Advisory |
| https://my.f5.com/manage/s/article/K000137416 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-02-14 17:15
Updated : 2024-12-12 19:10
NVD link : CVE-2024-23308
Mitre link : CVE-2024-23308
CVE.ORG link : CVE-2024-23308
JSON object : View
Products Affected
f5
- big-ip_application_security_manager
- big-ip_advanced_web_application_firewall
CWE
CWE-476
NULL Pointer Dereference
