Web Hack List

Collected research

Exploiting HSQLDB

Remote Code Execution in F5 Big‑IP

An Apache and Tomcat path-normalisation difference lets /..;/ in a URL slip past the F5 BIG-IP TMUI proxy rules and reach the hidden hsqldb servlet unauthenticated. Default HSQLDB credentials then allow arbitrary SQL, and its CALL statement invokes an F5 static method that evaluates Jython, giving unauthenticated remote code execution (CVE-2020-5902).

Record

Document
Remote Code Execution in F5 Big‑IP
Researcher
Mikhail Klyuchnikov and @m1ke_n1
Published by
PT SWARM
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Mikhail Klyuchnikov and @m1ke_n1, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .