Description
When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF) protection or when an NGINX server is configured with App Protect Bot Defense, undisclosed requests can disrupt new client requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Problem types
CWE-770 Allocation of Resources Without Limits or Throttling
Product status
17.5.0 before *
17.1.0 before 17.1.2
16.1.0 before *
15.1.0 before *
5.0.0 before *
4.0.0 before 4.7.0
Credits
F5
References
my.f5.com/manage/s/article/K000148512