Description
Due to the request smuggling vulnerability in the F5 BIG-IP server, an unauthenticated attacker can smuggle additional AJP requests for the Tomcat server bypassing authentication. A successful attack with this vulnerability may result in a takeover of the server.
Remediation
Upgrade to the latest version of F5 BIG-IP system
References
BIG-IP Configuration utility unauthenticated remote code execution vulnerability CVE-2023-46747
Compromising F5 BIG-IP With Request Smuggling | CVE-2023-46747
Related Vulnerabilities
IBM RTC Improper Restriction of XML External Entity Reference Vulnerability (CVE-2021-20502)
Oracle JRE CVE-2024-20919 Vulnerability (CVE-2024-20919)
Atlassian Jira Incorrect Authorization Vulnerability (CVE-2019-8446)
Oracle Database Server CVE-2012-0528 Vulnerability (CVE-2012-0528)
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-11588)