...
AVR will inject JavaScript although it should not.
AVR can invalidate a response, by injecting JavaScript in a page that is not actually an HTML page.
"Page Load Time" in analytic profile is turned on. Send HTTP request with content-type is text/html without the <head> tag.
Turn off "Page Load Time" in analytic profile
AVR now checks the Content-Type and the existence of the <head> header in the body of a response, before inserting CSPM JavaScript, so that it only injects the CSPM JavaScript into appropriately formatted HTML documents.
Click on a version to see all relevant bugs
F5 Integration
Learn more about where this data comes from
Bug Scrub Advisor
Streamline upgrades with automated vendor bug scrubs
BugZero Enterprise
Wish you caught this bug sooner? Get proactive today.