CVE-2023-50969 Details
Description
Thales Imperva SecureSphere WAF 14.7.0.40 allows remote attackers to bypass WAF rules via a crafted POST request, a different vulnerability than CVE-2021-45468.
A vulnerability in Thales Imperva SecureSphere Web Application Firewall (WAF) version 14.7.0.40 allows remote attackers to bypass WAF rules that inspect POST data. This could enable exploitation of vulnerabilities in protected web applications that would normally be blocked by the WAF. The issue arises from the WAF's handling of Content-Encoding headers, which can be manipulated to evade detection and filtering of malicious POST data.
Imperva has released an ADC rule update on February 26, 2024, to address this vulnerability. Imperva customers can find more information on the Imperva Support Portal.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 28, 2024CISA-ADP
Assessed Mar 29, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.imperva.com/bundle/v14.7-waf-administration-guide/page/9282.htm | CVE | Vendor |
| https://www.hoyahaxa.com/2024/03/imperva-waf-bypass-cve-2023-50969.html | CVE | ExploitRemedyTechnical Description |
| https://docs.imperva.com/bundle/v14.7-waf-administration-guide/page/9282.htm | [email protected] | Vendor |
| https://www.hoyahaxa.com/2024/03/imperva-waf-bypass-cve-2023-50969.html | [email protected] | ExploitRemedyTechnical Description |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Thales Imperva SecureSphere WAF | 14.7.0.40 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| Aug 27, 2024 | CVE Modified | CISA-ADP |
| May 14, 2024 | CVE Modified | [email protected] |
| Mar 28, 2024 | New CVE Received | [email protected] |
Volerion