A crafted request uri-path can cause modproxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
On F5OS-A beginning in version 1.2.0 to before 1.3.0 and F5OS-C beginning in version 1.3.0 to before 1.5.0, processing F5OS tenant file names may allow for command injection. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Processing F5OS tenant file names may allow for command injection.
When LDAP remote authentication is configured on F5OS, a remote user without an assigned role will be incorrectly authorized.
When LDAP remote authentication is configured on F5OS, a remote user without an assigned role will be incorrectly authorized.