Mar 27, 2026 - For details about updated CVE-2025-53521 (BIG-IP APM vulnerability), refer to K000156741.

Forum Discussion

Ranbir_183916's avatar
Ranbir_183916
Icon for Nimbostratus rankNimbostratus
Jan 23, 2015

Vulnerabilities "Server Information Disclosure" and "Missing Secure Attribute"

could somone suggest how to fix the below vulnerabilities.

 

"Server Information Disclosure" and "Missing Secure Attribute"

 

2 Replies

  • Hello Ranbir, it sounds like those two vulnerabilities were revealed in the output from a web application vulnerability scanner. A quick way to see if they're easily resolved is to create a security policy in ASM using the "third party vulnerability scanner" output option when you start the deployment wizard. Import the XML-based vulnerability output file into ASM, and then locate those two vulnerabilities in the list. It is possible that ASM will mark them as "resolvable" and you might be able to simply select each one in the GUI and then click "resolve" or "resolve and stage." At that point, you could run the scan again, and any vulnerabilities resolved by ASM should no longer appear.