PT-2019-18213 · F5 · F5 Big-Ip
Published
2019-07-03
·
Updated
2023-02-16
·
CVE-2019-6631
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
F5 BIG-IP versions 11.5.1 through 11.6.4
Description
The issue occurs when iRules perform HTTP header manipulation, potentially causing an interruption to service. This happens under specific circumstances when traffic is handled by a Virtual Server with an associated HTTP profile and the requests do not strictly conform to RFCs.
Recommendations
For F5 BIG-IP versions 11.5.1 through 11.6.4, consider disabling iRules that perform HTTP header manipulation until a patch is available. Restrict access to Virtual Servers with associated HTTP profiles to minimize the risk of exploitation. Avoid using HTTP header manipulation in iRules for these versions until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
F5 Big-Ip