Total vulnerabilities in the database
On BIG-IP Advanced WAF and BIG-IP ASM version 16.0.x before 16.0.1.2 and 15.1.x before 15.1.3 and NGINX App Protect on all versions before 3.5.0, when a cross-site request forgery (CSRF)-enabled policy is configured on a virtual server, an undisclosed HTML response may cause the bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Software | From | Fixed in |
---|---|---|
f5 / big-ip_application_security_manager | 16.0.0 | 16.0.1.2 |
f5 / big-ip_application_security_manager | 15.1.0 | 15.1.3.1 |
f5 / big-ip_advanced_web_application_firewall | 16.0.0 | 16.0.1.2 |
f5 / big-ip_advanced_web_application_firewall | 15.1.0 | 15.1.3.1 |
f5 / nginx_app_protect | 1.0.0 | 1.3.0.x |
f5 / nginx_app_protect | 2.0.0 | 2.3.0.x |
f5 / nginx_app_protect | 3.0.0 | 3.5.0 |