Possible vulnerability in F5 BIG-IP LTM – Improper input validation of the HTTP version number of the HTTP reqest allows any payload size and conent to pass through

Posted by Eitan Caspi on Jan 05

Initial note: The vendor has graded this issue as a vulnerability graded as “High” in my email exchange with it, but
eventually posted the issue as a “Know Issue”, so some of this issue’s characteristic that follows can be treated as
initial ones, as I ask the IS community to look into this issue and give a “second opinion” about it. Thank you.

Suggested severity level: High (per the vendor’s initial…

Leave a Reply