First published: Tue Apr 11 2017(Updated: )
The TMM SSO plugin in F5 BIG-IP APM 12.0.0 - 12.1.1, 11.6.0 - 11.6.1 HF1, 11.5.4 - 11.5.4 HF2, when configured as a SAML Identity Provider with a Service Provider (SP) connector, might allow traffic to be disrupted or failover initiated when a malformed, signed SAML authentication request from an authenticated user is sent via the SP connector.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Big-ip Access Policy Manager | =11.5.4 | |
F5 Big-ip Access Policy Manager | =11.6.0 | |
F5 Big-ip Access Policy Manager | =11.6.1 | |
F5 Big-ip Access Policy Manager | =12.0.0 | |
F5 Big-ip Access Policy Manager | =12.1.0 | |
F5 Big-ip Access Policy Manager | =12.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.