SAML Authentication Request Vulnerability in F5 BIG-IP APM
CVE-2016-7467
5.3MEDIUM
What is CVE-2016-7467?
The F5 BIG-IP APM's TMM SSO plugin has a vulnerability that could disrupt traffic when it processes a malformed, signed SAML authentication request. This occurs in the context of a SAML Identity Provider configured with a Service Provider connector, affecting specific versions of the product. The flaw allows an authenticated user to inadvertently send a malicious request, potentially triggering failover scenarios or causing operational disruptions.
Affected Version(s)
F5 BIG-IP APM 12.0.0 - 12.1.1, 11.6.0 - 11.6.1 HF1, 11.5.4 - 11.5.4 HF2