Session Awareness Vulnerability in F5 BIG-IP Web Application Security
CVE-2022-26890
What is CVE-2022-26890?
A vulnerability exists in F5 BIG-IP versions of Advanced WAF, ASM, and APM that can lead to the termination of the bd process. This occurs when these components are configured on a virtual server, and the ASM policy has Session Awareness enabled with the 'Use APM Username and Session ID' option. Undisclosed requests can exploit this configuration, potentially leading to service disruptions. It’s critical to monitor and address affected versions to maintain security and system stability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
BIG-IP Advanced WAF, ASM, and APM 16.1.x < 16.1.2.1
BIG-IP Advanced WAF, ASM, and APM 15.1.x < 15.1.5
BIG-IP Advanced WAF, ASM, and APM 14.1.x < 14.1.4.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved