Forum Discussion
Managing Vulnerabilities
I am going to reply to my own question as I probably should have read the Article a little closer.
https://support.f5.com/csp/article/K13114
Vulnerable component or feature Virtual servers are not vulnerable, but may proxy exploits to vulnerable servers
I am not on a vulnerable image: Versions known to be Not Vulnerable 11.1.0 and later
So I think this is a tagging issue with our Vuln Management system. I guess if anyone responds, do you think this is still an issue with F5 or an issue with Nexpose?
- Chris_GrantAug 04, 2018
Employee
Your vulnerability managing system is correctly reporting that there is a vulnerability, but in this case it's a vulnerability on the back end system that is being exposed through the BigIP. The correct place to patch this is in the back end system. Patching the BigIP, even if possible, would do nothing to patch the vulnerability your scanner is seeing, as we are simply passing on the vulnerable code from the back end.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com