Mar 27, 2026 - For details about updated CVE-2025-53521 (BIG-IP APM vulnerability), refer to K000156741.

Forum Discussion

Zafer_101134's avatar
Zafer_101134
Icon for Nimbostratus rankNimbostratus
Jan 13, 2011

asm capabilities encoded request

Hi

 

i m doing Xss attack to the ASM with

2 Replies

  • hoolio's avatar
    hoolio
    Icon for Cirrostratus rankCirrostratus
    Hi Zafer,

     

     

    ASM doesn't currently provide an option to base64 decode request components. But most web servers won't do this either so it's not a problem. If the web application does base64 decode whatever request component you're putting the base64 encoded attack string in, then you'd have a potential issue.

     

     

    What kind of app are you testing?

     

     

    Aaron
  • Hi hoolio

     

     

    the customer use apache tomcat.

     

    We tested several attack methods to the ASM and i can't find how to block encoded request based on hex and base64

     

     

    regards

     

    zafer