On BIG-IP Advanced WAF and BIG-IP ASM version 16.0.x before 16.0.1.2 and 15.1.x before 15.1.3 and NGINX App Protect on all versions before 3.5.0, when a cross-site request forgery (CSRF)-enabled policy is configured on a virtual server, an undisclosed HTML response may cause the bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Big-ip_advanced_web_application_firewall | F5 | 15.1.0 (including) | 15.1.3.1 (excluding) |
Big-ip_advanced_web_application_firewall | F5 | 16.0.0 (including) | 16.0.1.2 (excluding) |
Big-ip_application_security_manager | F5 | 15.1.0 (including) | 15.1.3.1 (excluding) |
Big-ip_application_security_manager | F5 | 16.0.0 (including) | 16.0.1.2 (excluding) |
Nginx_app_protect | F5 | 1.0.0 (including) | 1.3.0 (including) |
Nginx_app_protect | F5 | 2.0.0 (including) | 2.3.0 (including) |
Nginx_app_protect | F5 | 3.0.0 (including) | 3.5.0 (excluding) |