SV-230217r561165_rule
V-230217
SRG-APP-000435-NDM-000315
F5BI-DM-000290
CAT III
10
Configure a policy in the BIG-IP ASM module to enable the HTTPonly flag.
Log in to the Configuration utility.
Navigate to Security >> Options >> Application Security >> Advanced Configuration >> System Variables
Create the variable cookie_httponly_attr.
Set the Parameter to 1.
If the BIG-IP ASM module is not used to support user authentication, this is not applicable.
Navigate to Security >> Options >> Application Security >> Advanced Configuration >> System Variables
Verify cookie_httponly_attr is set to 1.
If the BIG-IP appliance is being used to authenticate users for web applications, the HTTPOnly flag must be set, this is a finding.
V-230217
False
F5BI-DM-000290
If the BIG-IP ASM module is not used to support user authentication, this is not applicable.
Navigate to Security >> Options >> Application Security >> Advanced Configuration >> System Variables
Verify cookie_httponly_attr is set to 1.
If the BIG-IP appliance is being used to authenticate users for web applications, the HTTPOnly flag must be set, this is a finding.
M
4036