CVE-2023-22422: HTTP profile vulnerability
On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, when a HTTP profile with the non-default Enforcement options of Enforce HTTP Compliance and Unknown Methods: Reject are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Other sources
When an HTTP profile with the non-default Enforcement options Enforce RFC Compliance and Unknown Methods: Reject are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate.
— F5
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-22422.
What is the severity level of CVE-2023-22422?
The severity level of CVE-2023-22422 is high.
Which versions of BIG-IP are affected by CVE-2023-22422?
BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3 are affected by CVE-2023-22422.
What are the affected software and their versions for CVE-2023-22422?
The affected software and their versions for CVE-2023-22422 include F5 Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager, F5 BIG-IP Analytics, F5 Big-ip Application Acceleration Manager, F5 BIG-IP Application Security Manager, F5 Big-ip Ddos Hybrid Defender, F5 Big-ip Domain Name System, F5 Big-ip Fraud Protection Service, F5 Big-ip Link Controller, F5 Big-ip Local Traffic Manager, F5 Big-ip Policy Enforcement Manager, and F5 Big-ip Ssl Orchestrator.
How can I fix CVE-2023-22422?
To fix CVE-2023-22422, you should update to BIG-IP versions 17.0.0.2 or later for 17.0.x and 16.1.3.3 or later for 16.1.x.