Operational Defect Database

BugZero found this defect 67 days ago.

F5 | 1485557

OAuth token not found for OAuth server with Bearer SSO

Last update date:

4/26/2024

Affected products:

BIG-IP

BIG-IP APM

Affected releases:

15.1.8

15.1.8.1

15.1.8.2

15.1.9

15.1.9.1

15.1.10

15.1.10.2

15.1.10.3

15.1.10.4

16.1.2.2

16.1.3

16.1.3.1

Fixed releases:

No fixed releases provided.

Description:

Severity: 3-Major ... Symptoms ... When the BIG-IP Administrator configures BIG-IP as OAuth RS with OAuth Bearer Single Sign On, WebSSO fails as an empty access token is included as a session variable. ... Impact ... BIG-IP Administrator fails to implement a successful OAuth Bearer SSO on OAuth RS. ... Conditions ... OAuth Scope sets different access_token variables except for the one that is acceptable by WebSSO. ... Workaround ... None

Additional Resources / Links

Share:

BugZero® Risk Score

What's this?

Coming soon

Status

New

Learn More

Search:

...