CVE-2024-23308

When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to a virtual server, undisclosed requests can cause the BD process to terminate. The condition results from setting the Request Body Handling option in the Header-Based Content Profile for an Allowed URL with "Apply value and content signatures and detect threat campaigns."  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*

History

12 Dec 2024, 19:10

Type Values Removed Values Added
CPE cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
References () https://my.f5.com/manage/s/article/K000137416 - () https://my.f5.com/manage/s/article/K000137416 - Vendor Advisory
First Time F5 big-ip Advanced Web Application Firewall
F5
F5 big-ip Application Security Manager

21 Nov 2024, 08:57

Type Values Removed Values Added
References () https://my.f5.com/manage/s/article/K000137416 - () https://my.f5.com/manage/s/article/K000137416 -
Summary
  • (es) Cuando una política BIG-IP Advanced WAF o BIG-IP ASM con una opción de Manejo del cuerpo de la solicitud se adjunta a un servidor virtual, las solicitudes no divulgadas pueden hacer que el proceso BD finalice. La condición resulta de configurar la opción Manejo del cuerpo de la solicitud en el perfil de contenido basado en encabezado para una URL permitida con "Aplicar firmas de valor y contenido y detectar campañas de amenazas". Nota: Las versiones de software que han llegado al final del soporte técnico (EoTS) no se evalúan

14 Feb 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-14 17:15

Updated : 2024-12-12 19:10


NVD link : CVE-2024-23308

Mitre link : CVE-2024-23308

CVE.ORG link : CVE-2024-23308


JSON object : View

Products Affected

f5

  • big-ip_application_security_manager
  • big-ip_advanced_web_application_firewall
CWE
CWE-476

NULL Pointer Dereference