Mar 27, 2026 - For details about updated CVE-2025-53521 (BIG-IP APM vulnerability), refer to K000156741.

Forum Discussion

Arjun's avatar
Arjun
Icon for Nimbostratus rankNimbostratus
Aug 04, 2024

Attack requests with GET method

Observed certain attacks with GET requests. The attacks were observed for only one minute time and looks like run with scan tool. Although, I am not very well versed on application attack vectors.

Could someone help me understand these requests and their impact on the application. The F5 passed the requests but mainly cause the urls have wildcard in staging.

 

GET
/webui
/manager/html
/solr/admin/cores
/favicon.ico
/latest/meta-data/identity-credentials/ec2/security-credentials/ec2-instance
/solr/admin/collections
/openstack/latest
/Onboarding/Import
/dynamic/instance-identity/document
/file=http:/www.w3.org/1999/xhtml

POST
/solr/gettingstarted_shard1_replica_n1/config
/jars/upload
/Onboarding/Import
/WEB_VMS/LEVEL15/
/api/session
/cps/test_backup_server
/ZMC_Admin_Login
/api/authentication/login

 

Thank you all

2 Replies

No RepliesBe the first to reply