Loading...
Loading...
After upgrading from 11.4.1 to 11.6.0, 11.6.1 or 12.0.0, you see a lot of "Illegal meta character in value" false positives on your XML content. The flagged character are valid within XML (<, >, /, :, etc.) and the affected URLs are associated with legitimate XML profiles via header-based content profiles. From the security event report, one can see that the invalid characters are for the global UNNAMED wildcard parameter and that the request is a multipart POST.
False positive violations could happen on the parameter enforcement (as it's not a parameter content but XML).
XML profile is assigned to the wildcard URL and having Header-Based Content profile.
N/A
Fixed a scenario when an XML profile is configured on the URL to not parse multipart root XML as form-data parameter, but only as XML.
Click on a version to see all relevant bugs
F5 Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.