Skip to content
View in the app

A better way to browse. Learn more.

Gear Crushers

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Is the ASM policy blocking specific attack signature?

Featured Replies

Goal is to make sure CVE-2017-10271-29308 is being blocked

To check this you can simply do the following.

  1. Log into the GUI of the device and select the correct partition in the upper right hand corner of the GUI. In this case I had to choose the "Production" partition since that is where the ASM policy exists.
  2. Navigate to Security  ››  Application Security : Attack Signatures : Attack Signatures List.
  3. Change the "Current edited policy" to the correct policy. In this case I chose the main default "ASMGlobalPolicy". You can see that the policy is also set to "blocking".
  4. Now click "Show Filter Details" to expand the advanced search. Enter 200004174 into the "Signature ID" field and click the "Go" button.
  5. After clicking the "Go" button simply scroll down and you will see the attack signature listed. I believe the name of it is "Sensitive Java class detected in XML". Then all we need to do is look at the right hand side to see that the "Block" and "Enabled" columns have a value of "Yes". In my repro they do which indicates that the attack signature is set to block for this ASM policy.

In short, any virtual server that has the "ASMGlobalPolicy" applied to it should be safe from CVE-2017-10271 as mentioned in the DevCentral article. https://devcentral.f5.com/articles/oracle-weblogic-wls-security-component-remote-code-execution-cve-2017-10271-29308

Create an account or sign in to comment

Important Information

By using this site, you agree to our Terms of Use.

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.