Foundry Networks ServerIron switches do not decode URIs when applying "url-map" rules, which could make it easier for attackers to cause the switch to forward traffic to a different server than intended and exploit vulnerabilities that would otherwise be inaccessible.
| Software | From | Fixed in |
|---|---|---|
| foundrynet / serveriron | 7.1.09 | 7.1.09.x |
| foundrynet / serveriron | xl | xl.x |
| foundrynet / serveriron | 400 | 400.x |
| foundrynet / serveriron | 5.1.10t12 | 5.1.10t12.x |
| foundrynet / serveriron | 800 | 800.x |
| foundrynet / serveriron | xl_g | xl_g.x |
| foundrynet / serveriron | 6.0 | 6.0.x |