Description
Due to the request smuggling vulnerability in the F5 BIG-IP server, an unauthenticated attacker can smuggle additional AJP requests for the Tomcat server bypassing authentication. A successful attack with this vulnerability may result in a takeover of the server.
Remediation
Upgrade to the latest version of F5 BIG-IP system
References
BIG-IP Configuration utility unauthenticated remote code execution vulnerability CVE-2023-46747
Compromising F5 BIG-IP With Request Smuggling | CVE-2023-46747
Related Vulnerabilities
XOOPS Other Vulnerability (CVE-2005-0743)
Django URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2017-7233)
SharePoint CVE-2021-34468 Vulnerability (CVE-2021-34468)
Oracle Database Server CVE-2006-3705 Vulnerability (CVE-2006-3705)
Jenkins Improper Access Control Vulnerability (CVE-2015-5325)