For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

AshuA_246482's avatar
AshuA_246482
Icon for Nimbostratus rankNimbostratus
Nov 29, 2017

cookie & requestVerificationToken is set without the HttpOnly Cookie parameter

Pen test finding below: How to set cookie & requestVerificationToken with the HttpOnly Cookie parameter on LTM running on 11.6   Risk : When a cross-site scripting vulnerability is present, an at...