On BIG-IP APM 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, and 13.1.0-13.1.3.3, when multiple HTTP requests from the same client to configured SAML Single Logout (SLO) URL are passing through a TCP Keep-Alive connection, traffic to TMM can be disrupted.
2020-10-29T16:15:15.587
2024-11-21T05:34:51.433
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:A/AC:L/Au:N/C:N/I:N/A:P
6.5
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | f5 | big-ip_access_policy_manager | < 13.1.3.4 | Yes |
| Application | f5 | big-ip_access_policy_manager | < 14.1.2.4 | Yes |
| Application | f5 | big-ip_access_policy_manager | < 15.1.1 | Yes |