RULE(RULE ID:338032)

Rule General Information
Release Date: 2024-05-21
Rule Name: F5 BIG-IP Next Central Manager API SQL Injection Vulnerability (CVE-2024-26026)
Severity:
CVE ID:
Rule Protection Details
Description: An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference: https://my.f5.com/manage/s/article/K000138733
Solutions
Refer to the announcement or patch by the vendor: https://my.f5.com/manage/s/article/K000138733