Mar 27, 2026 - For details about updated CVE-2025-53521 (BIG-IP APM vulnerability), refer to K000156741.

Forum Discussion

A_hassanein's avatar
A_hassanein
Icon for Nimbostratus rankNimbostratus
May 20, 2026

Guest Role User Lost Visibility in ASM/WAF Module – LTM Working Fine

Hi community,

 

I'm troubleshooting a strange issue on our F5 BIG-IP and hoping someone has run into this before.

 

Environment:

- Module: ASM (WAF)

- User Role: Guest

- Partition Access: All Partitions

 

Problem:

A user with the Guest role and access to all partitions suddenly lost the ability to view any information in the ASM module. When navigating to Security > Application Security > Policies, the table shows "No records to display" — even though policies exist and are active and viewable from other non-guest accounts.

 

The strange part: LTM is working perfectly fine for this user. They can view virtual servers, pools, nodes, etc. without any issue. The problem is isolated to ASM only.

 

Any pointers would be greatly appreciated. Happy to share outputs if needed.

 

Thanks!

1 Reply

  • update: 

    i get get authorization errors like the following in response of request that fetch ASM related data "Authorization failed: user=https://localhost/mgmt/cm/system/authn/providers/tmos/{UUID}/users/{UUID} resource=/mgmt/tm/asm/policies verb=GET uri:http://localhost:<port>/mgmt/tm/asm/policies sernder:<ip>"