For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Rasool1224's avatar
Rasool1224
Icon for Nimbostratus rankNimbostratus
Oct 14, 2018

cspm issue in 14 ASM

f5avr0509501052aaaaaaaaaaaaaaaa_cspm_

 

Dear All,

 

i have 14 version of big-ip, suddenly my applicaiton stop working and it shows f5avr0509501052aaaaaaaaaaaaaaaa_cspm_

 

ookie: f5_cspm=1234; __utmz=247719320.1538483427.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); _ga=GA1.2.1761850763.1538483427; __utma=247719320.1761850763.1538483427.1538917942.1538989690.5; ASP.NET_SessionId=pa4qmyfmxljfv3wwilxig24q; TS017f2633=0179b20df1dddee51daf51b18571454e4ac85e77066891d3e74e594c0dab0908abdc4cadbdfe59bbdd1f8c2bd5b37dee4e4655e5df9f01c096620595f68104c879914ed5cc117295196a3c193e9d3d9b4dc0f41f5c0d65d8d6526f9a4eb84d13ead68b3101

 

can any one suggest me how to get rid of this ....

 

thank you

 

3 Replies

  • Not sure what you are trying to show us. Where is "f5avr0509501052aaaaaaaaaaaaaaaa_cspm_" showing in the flow?

     

    Perhaps you could reformat the output in another way.

     

  • Below is the request information from application logs:

    GET / HTTP/1.1 Host: sub.example.com Connection: keep-alive Purpose: prefetch Upgrade-Insecure-Requests: 1 User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,/;q=0.8 Accept-Encoding: gzip, deflate Accept-Language: en-US,en;q=0.9

     

    Cookie: __utmz=247719320.1537461876.20.13.utmcsr=nammashippinglines.com|utmccn=(referral)|utmcmd=referral|utmcct=/; _ga=GA1.2.2115080606.1519762427; __utma=247719320.2115080606.1519762427.1537461876.1538420250.21; ASP.NET_SessionId=qcjoy1f0grxg321em2ibf2fu; lang=1; TS01303211=0179b20df1505bae2bd972621930f4986ae56c564a07a47b4016524eeeeff6f358125b0cd50b700027535428689327bf8a7bef52aeb7a39229569c462e6f1ba323b9377405ac9611d1178efc3f62f6d0bfdef0043cf1cf0931269413767c485b30b6424022; TS01d9b2ea=0179b20df1736832133a19fd353e81efaf5bcfe2f1579d76d55c5231720b60add581c126a396d9aa2fcd5a935d5f7aa85f2fc6c48cd271e0d143cd2de294e154d8c5b82d09b6161a5783370f6cfb8095bdb90467d0; TS017f2633=0179b20df172f19e115e84c82aef19ff2dfba49ff7abb6640609c7aa5a1027c610dcee818ac6f5eb44e0767429293807d24db33d2376e1fab226768482b297b55a6430b48a9dd8a2f42b194417056de2727eec2e43; f5avr0509501052aaaaaaaaaaaaaaaa_cspm_=EPKNDHFDKLPDEEAHJCGNDMEAPDNCLIGABHPMALHDFCJOABLIOOEKJHONNCDBDCGOCGIDNNHODGACCHLFEMLHJPHGACJAPGLOMEFFFMIKEAGKHJJEABILGEIDEAHBAPIN

    but once i remove the http profile then it works, please advice your suggestion.

     

    thank you

     

  • Matched Cookie: f5avr0509501052aaaaaaaaaaaaaaaa_cspm_ Here is the path "Security ›› Application Security : Policy Building : Traffic Learning"

     

    Now start appearing in all applications,

     

    any advices... thank you