F5-K000132665: High severity F5 BIG-IP vulnerability

Published Feb 22, 2023
·
Updated

Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client.

Affected Software

8 affected componentsFixes available
F5 BIG-IP>=17.5.0<=17.5.1, >=17.1.0<=17.1.2
17.5.1.117.1.3
F5 BIG-IP>=16.1.0<=16.1.6
F5 BIG-IP>=15.1.0<=15.1.10
F5 BIG-IP>=14.1.0<=14.1.5
F5 BIG-IP>=13.1.0<=13.1.5
F5 F5OS-A>=1.8.0<=1.8.4, >=1.5.1<=1.5.4, >=1.3.0<=1.3.2
1.8.4
F5 F5OS-C>=1.8.0<=1.8.2, >=1.6.0<=1.6.4, >=1.5.0<=1.5.1, >=1.3.0<=1.3.2
F5 Traffix SDC=5.2.0

Event History

Feb 22, 2023
Advisory Published
via F5·12:02 AM
Data Sourced
via F5·12:02 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of F5-K000132665?

The severity of F5-K000132665 is critical due to the potential exposure of security-related headers.

2

How do I fix F5-K000132665?

To fix F5-K000132665, update your system to Apache HTTP Server version 2.4.55 or later.

3

Which products are affected by F5-K000132665?

F5-K000132665 affects versions of F5 BIG-IP, F5OS-A, F5OS-C, and Traffix SDC before specific versions as detailed in the advisory.

4

What are the risks associated with F5-K000132665?

The risks associated with F5-K000132665 include possible exposure of critical security headers in the response body to clients, compromising security.

5

How can I identify if I'm affected by F5-K000132665?

You can identify if you are affected by F5-K000132665 by checking the version of Apache HTTP Server and associated F5 products in use.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203