Collected research
Exploiting HSQLDB
Remote Code Execution in F5 Big‑IP
An Apache and Tomcat path-normalisation difference lets /..;/ in a URL slip past the F5 BIG-IP TMUI proxy rules and reach the hidden hsqldb servlet unauthenticated. Default HSQLDB credentials then allow arbitrary SQL, and its CALL statement invokes an F5 static method that evaluates Jython, giving unauthenticated remote code execution (CVE-2020-5902).
Record
- Document
- Remote Code Execution in F5 Big‑IP
- Researcher
- Mikhail Klyuchnikov and @m1ke_n1
- Published by
- PT SWARM
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Mikhail Klyuchnikov and @m1ke_n1, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .