CVE-2016-7467: Input Validation
The TMM SSO plugin in F5 BIG-IP APM 12.0.0 - 12.1.1, 11.6.0 - 11.6.1 HF1, 11.5.4 - 11.5.4 HF2, when configured as a SAML Identity Provider with a Service Provider (SP) connector, might allow traffic to be disrupted or failover initiated when a malformed, signed SAML authentication request from an authenticated user is sent via the SP connector.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7467?
CVE-2016-7467 is rated as a high severity vulnerability due to its potential to disrupt traffic and initiate failover scenarios.
How do I fix CVE-2016-7467?
To fix CVE-2016-7467, you should upgrade the F5 BIG-IP APM to a version that is not affected by this vulnerability, such as 12.1.1 or later.
What software versions are affected by CVE-2016-7467?
CVE-2016-7467 affects F5 BIG-IP Access Policy Manager versions 11.5.4 to 11.5.4 HF2, 11.6.0 to 11.6.1, and 12.0.0 to 12.1.1.
What is the impact of CVE-2016-7467 on SAML authentication?
The impact of CVE-2016-7467 on SAML authentication can lead to disruption of traffic or unintended failover when handling malformed signed SAML requests.
Is CVE-2016-7467 specific to any configuration of F5 BIG-IP?
Yes, CVE-2016-7467 is specific to F5 BIG-IP APM when configured as a SAML Identity Provider with a Service Provider connector.