PT-2019-18213 · F5 · F5 Big-Ip
CVE-2019-6631
·
Publicado
2019-07-03
·
Atualizado
2023-02-16
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
F5 BIG-IP versions 11.5.1 through 11.6.4
Description
The issue occurs when iRules perform HTTP header manipulation, potentially causing an interruption to service. This happens under specific circumstances when traffic is handled by a Virtual Server with an associated HTTP profile and the requests do not strictly conform to RFCs.
Recommendations
For F5 BIG-IP versions 11.5.1 through 11.6.4, consider disabling iRules that perform HTTP header manipulation until a patch is available. Restrict access to Virtual Servers with associated HTTP profiles to minimize the risk of exploitation. Avoid using HTTP header manipulation in iRules for these versions until the issue is resolved.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
F5 Big-Ip