2026-09-22 15:21 UTC
@fuzzyfuzzyfungus@cyberplace.social
When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server
My understanding is that the interface exposed with an access policy and OAuth profile is vulnerable, regardless of where the management interfaces are.
So if your APM is in front of an application and using an OAuth profile for access control, it would apparently be vulnerable.
I think they specified "no control plane exposure" so people didn't assume they're protected just because their management interfaces aren't exposed. Which is such a common approach to these vulns. This adds urgency.
Replies (0)
No replies.