Forum Discussion

THE_BLUE's avatar
THE_BLUE
Icon for Cirrostratus rankCirrostratus
Jul 08, 2025

IDOR and F5

Does F5 block IDOR vulnerability ? i think this is logical authorization flaw which should be fixed from application level as the WAF treat that as normal url . I'm right ? the case is when you change the id in url you can reach other user profile 

1 Reply

  • Hi THE_BLUE​ 

    You are right, WAF will stil see a valid request, so no block.

    You will need to fixed in app or use a user context aware mechanish like APM
    Check this