Description
Due to the request smuggling vulnerability in the F5 BIG-IP server, an unauthenticated attacker can smuggle additional AJP requests for the Tomcat server bypassing authentication. A successful attack with this vulnerability may result in a takeover of the server.
Remediation
Upgrade to the latest version of F5 BIG-IP system
References
BIG-IP Configuration utility unauthenticated remote code execution vulnerability CVE-2023-46747
Compromising F5 BIG-IP With Request Smuggling | CVE-2023-46747