<?xml version="1.0"?>
<rss version="2.0"><channel><title>NetScaler Application Security Latest Topics</title><link>https://community.stage.citrix.com/forums/forum/1009-netscaler-application-security/</link><description>NetScaler Application Security Latest Topics</description><language>en</language><item><title>Unable to see rate limit logs in netscaler</title><link>https://community.stage.citrix.com/forums/topic/258664-unable-to-see-rate-limit-logs-in-netscaler/</link><description><![CDATA[<p>Dear sir,</p><p>We have configured ip rate limit and we can see only hits, action taken <a rel="external nofollow" href="https://things.Buy">things. But we are unable to see ip rate limit logs.</a></p>
<p><a href="//media.invisioncic.com/r328636/monthly_2026_01/17676147639706718601653865802549.jpg.8fcfa4dc7b7d5af01a05baa19af58d3f.jpg" class="ipsAttachLink ipsAttachLink_image" ><img data-fileid="39473" src="//media.invisioncic.com/r328636/monthly_2026_01/17676147639706718601653865802549.thumb.jpg.f0a3b5b71ff73bf3c01b3a881b85d890.jpg" height="750" width="1000" class="ipsImage ipsImage_thumbnailed" alt="17676147639706718601653865802549.jpg" loading='lazy'></a></p>]]></description><guid isPermaLink="false">258664</guid><pubDate>Mon, 05 Jan 2026 12:06:42 +0000</pubDate></item><item><title>Rate limiting with traffic rate policy</title><link>https://community.stage.citrix.com/forums/topic/256684-rate-limiting-with-traffic-rate-policy/</link><description><![CDATA[<p>Hello,<br>we have configured a rate limit according to these instructions.<br><a rel="external nofollow" href="https://docs.netscaler.com/en-us/citrix-adc/current-release/appexpert/rate-limiting/configuring-binding-traffic-rate-policy1">https://docs.netscaler.com/en-us/citrix-adc/current-release/appexpert/rate-limiting/configuring-binding-traffic-rate-policy1</a></p><p>However, we still have problems with the drop if there are too many requests.</p><p>The configured audit log message is shown in the log.</p><p>Only the drop is not carried out.</p><p>We also do not see any hits or sessions in the limit identifier.</p><p>Hits and Action Taken are not counted up.</p><p>We have set the threshold to 1 and the time Slice to 1000000 for testing but no drop.</p><p>The audit message is written but the drop does not occur.</p><p>A test policy with TRUE as expression works.</p><p>Many thanks for your help<br><br>Sven</p>]]></description><guid isPermaLink="false">256684</guid><pubDate>Tue, 15 Jul 2025 08:50:42 +0000</pubDate></item><item><title>Introducing a Lightweight SOAR Solution for Citrix NetScaler with n8n.io</title><link>https://community.stage.citrix.com/forums/topic/258434-introducing-a-lightweight-soar-solution-for-citrix-netscaler-with-n8nio/</link><description><![CDATA[<p>Hello Netscaler passionate. I just wanted to share the project I've been working on for a while and that might be of interest to you.</p><p>It is about adapting the Netscaler configuration against rate limiting attacks that you might incur some day by using an automation software called n8n.</p><figure data-og-url="https://medium.com/@stefano.baronio/introducing-a-lightweight-soar-solution-for-citrix-netscaler-with-n8n-io-df5698559c38" data-og-description="Greetings, defenders of the digital realm! Tired of manually blocking those pesky attackers hitting your NetScaler? I feel your pain…" data-og-image="https://miro.medium.com/v2/da:true/resize:fit:1200/0*pNE1Sm3LhYpXNuIi" data-og-title="Introducing a Lightweight SOAR Solution for Citrix NetSca..." data-og-site_name="Medium" data-og-favicon_url="https://miro.medium.com/v2/resize:fill:304:304/10fd5c419ac61637245384e7099e131627900034828f4f386bdaa47a74eae156" data-og-image_width="1200" data-og-image_height="676" data-og-user_text="https://medium.com/@stefano.baronio/introducing-a-lightweight-soar-solution-for-citrix-netscaler-with-n8n-io-df5698559c38" class="ipsEmbedded_og ipsEmbedded"><div class="ipsEmbedded_og__site-name"><img class="ipsEmbedded_og__favicon" src="https://miro.medium.com/v2/resize:fill:304:304/10fd5c419ac61637245384e7099e131627900034828f4f386bdaa47a74eae156" alt=""><h5>Medium</h5></div><img class="ipsEmbedded_og__image" src="https://miro.medium.com/v2/da:true/resize:fit:1200/0*pNE1Sm3LhYpXNuIi" alt="No image preview" width="1200" height="676" loading="lazy"><figcaption><h3 class="ipsEmbedded_og__title">Introducing a Lightweight SOAR Solution for Citrix NetSca...</h3><div class="ipsEmbedded_og__description">Greetings, defenders of the digital realm! Tired of manually blocking those pesky attackers hitting your NetScaler? I feel your pain…</div></figcaption></figure>]]></description><guid isPermaLink="false">258434</guid><pubDate>Tue, 09 Sep 2025 15:27:00 +0000</pubDate></item><item><title>Automatic "banned" list if a WAF security protection has been hit?</title><link>https://community.stage.citrix.com/forums/topic/253468-automatic-banned-list-if-a-waf-security-protection-has-been-hit/</link><description><![CDATA[<p>
	Hi
</p>

<p>
	After implementing alot of WAF, i see that there is alot of scans of known attacks.
</p>

<p>
	10 of 11 requests might be blocked and 1 gets through.
</p>

<p>
	Is there a way (maybe with variables) to add a client src ip to a temporary banned list, if a specific ip has had 2(or higher) number of blocks within a timespan of 5 mins?
</p>

<p>
	1 solution could be to redirect the user to a landing page behind a LBVS, and have some magic here. If you had hit this vServer, you have done something you shouldnt... although that would require the user/bot to follow the redirect that NS is sending, and they are properly not going to do that.
</p>

<p>
	Is there a way to test based on the outcome of a WAF policy in the PI-expressions?
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">253468</guid><pubDate>Tue, 03 Dec 2024 15:06:56 +0000</pubDate></item><item><title>Authorization to access CITRIX for workstations without internet.</title><link>https://community.stage.citrix.com/forums/topic/250707-authorization-to-access-citrix-for-workstations-without-internet/</link><description><![CDATA[<p>
	Hello We have workstations that do not have full access to the internet and web service, how can we only authorize citrix to these workstations, knowing that our firwall only allows the authorization of IP addresses (level 3) and not complete addresses (level 7) https:\\***.**
</p>
]]></description><guid isPermaLink="false">250707</guid><pubDate>Wed, 01 Feb 2023 07:28:58 +0000</pubDate></item><item><title>NetScalerWAF Signatures for Microsoft Sharepoint CVEs</title><link>https://community.stage.citrix.com/forums/topic/256721-netscalerwaf-signatures-for-microsoft-sharepoint-cves/</link><description><![CDATA[<p><strong>ToolShell threat emerges: NetScaler WAF delivers protection</strong></p><p>In recent weeks, several CVEs have been disclosed for Microsoft SharePoint, exposing organizations to remote code execution and authentication bypass risks. NetScaler has released WAF signatures to protect against these vulnerabilities.</p><p><strong>Overview</strong></p><p>On July 8, 2025, Microsoft announced CVE-2025-49704 and CVE-2025-49706 initially discovered by Viettel Cyber Security researchers at the Pwn2Own hacking competition in  Berlin. The researchers demonstrated how the flaws could be chained together to bypass authentication and execute code within a SharePoint environment. The latter two i.e. CVE-2025-53770 and CVE-2025-5377` emerged on 20th and 21st July respectively, when attackers demonstrated the original patches were inadequate. </p><p>The following breakdown summarizes each CVE and how it affects SharePoint environments.</p><p>	•	<strong>CVE‑2025‑49704, CVSS-8.8</strong> - An authenticated attacker can execute arbitrary code on a target server due to a critical remote code execution (RCE) vulnerability in Microsoft SharePoint. This flaw arises from unsafe deserialization of user-supplied data, allowing attackers to upload specially crafted payloads that are then processed and executed within the SharePoint application's context.</p><p>	•	<strong>CVE‑2025‑49706, CVSS-6.5 </strong>- This is a critical authentication spoofing vulnerability in Microsoft SharePoint that allows a remote, unauthenticated attacker to bypass authentication controls and impersonate a legitimate user. Discovered and demonstrated during Pwn2Own 2024 by Viettel Cyber Security researchers, this flaw enables threat actors to initiate requests that appear to originate from a trusted, authenticated identity — even though no credentials are provided.</p><p>	•	<strong>CVE‑2025‑53770, CVSS-9.8</strong> - This is a patch bypass vulnerability in Microsoft SharePoint that re-enables remote code execution (RCE) by undermining the fix for CVE‑2025‑49704. Although Microsoft initially addressed the issue by blocking unsafe deserialization in SharePoint’s web components, attackers found that slight modifications to the original exploit could still trigger RCE.</p><p>	•	<strong>CVE‑2025‑53771, CVSS-6.5</strong> - This is a patch bypass vulnerability in Microsoft SharePoint that allows an attacker to bypass authentication mechanisms, even after CVE-2025-49706 was originally patched. This means that although Microsoft released an update in July 2025 to fix the original spoofing vulnerability (CVE-2025-49706), this new CVE indicates the original patch could be bypassed through small modifications to the exploit technique.</p><p>For additional details on the vulnerabilities, please refer to the official <a rel="external nofollow" href="https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/">Microsoft</a> blog.</p><p>How NetScaler WAF mitigates these CVEs</p><p>NetScaler WAF provides layered, signature-based protection designed to immediately detect and block exploit attempts targeting known vulnerabilities. </p><p>Version 157 of the NetScaler WAF signatures includes coverage for all four SharePoint CVEs described above. With these signatures in place, customers can mitigate these threats without needing to rely solely on software patch cycles.</p><p>Action recommended</p><p>To ensure your environment is protected:</p><p>1. Confirm you have the latest version (v157) of the NetScaler WAF signatures</p><p>2. Verify that WAF protections are enabled and in BLOCK mode for production environments</p><p>3. Review your logs and alerting to ensure visibility into blocked CVE-related traffic</p><p>Need help configuring or validating protection? Reach out to your NetScaler representative or consult our WAF <a rel="external nofollow" href="https://docs.netscaler.com/en-us/citrix-adc/current-release/application-firewall/signatures">documentation</a> for step-by-step guidance. Even in air-gapped or restricted environments, NetScaler makes it easy to manually download and apply WAF signature updates. This flexibility ensures strong protection in high-security or regulated deployments — without compromising ease of use. For instructions on how to turn on NetScaler WAF, see the <a rel="external nofollow" href="https://docs.netscaler.com/en-us/citrix-adc/current-release/application-firewall/deploymentguide.html">NetScaler WAF deployment guide.</a></p><p>WAF signatures are a key component of NetScaler’s hybrid security model and they can be updated independently of firmware upgrades, enabling faster response times to emerging threats, especially if you’re using <a rel="external nofollow" href="https://docs.netscaler.com/en-us/netscaler-console-service/overview.html">NetScaler Console</a> to manage your NetScaler infrastructure, NetScaler console is available both as an on-prem solution and a cloud service and if you have either the Universal Hybrid Multi-Cloud (UHMC) or Citrix Platform License (CPL), you already own entitlements to this capability across all your NetScaler instances. </p><p></p>]]></description><guid isPermaLink="false">256721</guid><pubDate>Mon, 28 Jul 2025 20:28:14 +0000</pubDate></item><item><title>SharePoint ZeroDay CVE-2025-53770 WAF Signature?</title><link>https://community.stage.citrix.com/forums/topic/256699-sharepoint-zeroday-cve-2025-53770-waf-signature/</link><description><![CDATA[<p><span style="font-family: inherit">Could you please advise if there are plans to release a WAF signature to mitigate CVE-2025-53770?</span><br><br><span style="font-family: inherit">Maybe some ideas what can be blocked manually using a responder policy?</span></p>]]></description><guid isPermaLink="false">256699</guid><pubDate>Mon, 21 Jul 2025 21:02:42 +0000</pubDate></item><item><title>WAF for 14.1 AAA/VPN</title><link>https://community.stage.citrix.com/forums/topic/256675-waf-for-141-aaavpn/</link><description><![CDATA[<p><a rel="external nofollow" href="https://docs.netscaler.com/en-us/citrix-adc/current-release/aaa-tm/waf-protection-endpoint-urls.html">https://docs.netscaler.com/en-us/citrix-adc/current-release/aaa-tm/waf-protection-endpoint-urls.html</a></p><p>After enabling this feature, how does one manage it?  I don't see anything enabled under Security;  customer has an advanced NS license.  </p><p>Where are the profile/policies, relaxation rules, etc?  Is it all CLI then?</p>]]></description><guid isPermaLink="false">256675</guid><pubDate>Wed, 09 Jul 2025 20:21:56 +0000</pubDate></item><item><title>Issues using OAUTH SP in combination with EntraID App Registration</title><link>https://community.stage.citrix.com/forums/topic/256678-issues-using-oauth-sp-in-combination-with-entraid-app-registration/</link><description><![CDATA[<p>Hi Community,</p><p></p><p>I followed the instructions for creating an entraid app registration to work work with netscaler oauth sp.<br><br>Jul 10 14:37:12 &lt;local0.info&gt; 172.31.3.151  07/10/2025:12:37:12 GMT vacnstfi31 0-PPE-0 : default AAATM Message 622847 0 :  "OAUTH RESP: ns_aaa_oauth_resp_handler, response code 400 is not 200 OK, bailing out"</p><p>Jul 10 14:37:12 &lt;local0.info&gt; 172.31.3.151  07/10/2025:12:37:12 GMT vacnstfi31 0-PPE-0 : default SSLVPN Message 622848 0 :  "AAA Client Handler: Found extended error code 1310727, ReqType 16386 request /oauth/login?code=1 ...<br><br>Browser is displaying "Error trying to validate Access Token. Please contact your administrator". OAUTH Server State is "COMPLETE". In EntraID Sign-in Logs I see success. I am pretty sure I copied the client secret correctly.</p><p></p><p>What can be issues for that "Error trying to validate Access Token"? What is "extended error code 1310727"?</p><p></p><p>Can anyone help here?</p><p></p><p>Regards,</p>]]></description><guid isPermaLink="false">256678</guid><pubDate>Thu, 10 Jul 2025 13:38:10 +0000</pubDate></item><item><title>Password spraying attacks on NetScaler Gateway</title><link>https://community.stage.citrix.com/forums/topic/253742-password-spraying-attacks-on-netscaler-gateway/</link><description><![CDATA[<p>
	Hi,
</p>

<p>
	We have deployed the WAF together with the Password spraying blocks following this blog:
</p>

<p>
	<a href="https://www.citrix.com/blogs/2024/12/13/password-spraying-attacks-netscaler-december-2024/" rel="external nofollow">https://www.citrix.com/blogs/2024/12/13/password-spraying-attacks-netscaler-december-2024/</a>
</p>

<p>
	For the most part it seems to work just fine, but we've noticed that macOS clients with SAC (with the latest version naturally) can't connect if we deploy the rules as it is.
</p>

<p>
	As a clumsy workaround I have just adjusted the policy to include this bit (my patternset is called "ps_legacy_auth_password_spray":
</p>

<p>
	<span style="font-family:'Courier New', Courier, monospace;">HTTP.REQ.URL.SET_TEXT_MODE(IGNORECASE).CONTAINS_ANY("ps_legacy_auth_password_spray") <span style="background-color:#f1c40f;">&amp;&amp; !HTTP.REQ.HEADER("User-Agent").CONTAINS("Macintosh")</span></span>
</p>

<p>
	This way we can get the macOS' connected, but then of course if the attacker would send a User-Agent HTTP header including "Macintosh" they could still spray the destination environment.
</p>

<p>
	Has anyone else faced the same issue, and if so, have you found a better solution?
</p>
]]></description><guid isPermaLink="false">253742</guid><pubDate>Thu, 03 Apr 2025 11:04:23 +0000</pubDate></item><item><title>Gateway WAF Parameter is invalid as per API Spec: (ns-vpn-spec) for Endpoint</title><link>https://community.stage.citrix.com/forums/topic/256497-gateway-waf-parameter-is-invalid-as-per-api-spec-ns-vpn-spec-for-endpoint/</link><description><![CDATA[<p>
	Has anyone else faced an issue with Gateway WAF where you start getting the following error:
</p>

<blockquote class="ipsQuote" data-ipsquote="">
	<div class="ipsQuote_citation">
		Quote
	</div>

	<div class="ipsQuote_contents">
		<p>
			Apr 28 14:02:21 &lt;local0.info&gt; {nsip}  04/28/2025:14:02:21 GMT {hostname} 0-PPE-0 : default APPFW APPFW_SCHEMA_PARAMETER_INVALID 1214 0 :  X 4302-PPE0 - ns-vpn-default-appfw-profile Parameter is invalid as per API Spec: (ns-vpn-spec) for Endpoint: (GET https://{gw-gqdn}/cgi/setclient?java) &lt;blocked&gt;<br />
			Apr 28 14:02:22 &lt;local0.info&gt; {nsip}  04/28/2025:14:02:22 GMT {hostname} 0-PPE-2 : default SNMP TRAP_SENT 0 0 :  appfwSchemaParameterInvalid (appfwLogMsg = "X 4302-PPE0 - ns-vpn-default-appf...", nsPartitionName = default)
		</p>
	</div>
</blockquote>

<p>
	I just have the very basic AppFw setup for Gateway + the explicit Deny rules for the Password Spraying.
</p>

<p>
	I could see the front page load, but once we try logging in the connection is reset. Disabling the AppFw protection from the AAA global settings instantly fixed this issue (was configured for AUTH and VPN).
</p>
]]></description><guid isPermaLink="false">256497</guid><pubDate>Mon, 28 Apr 2025 14:27:05 +0000</pubDate></item><item><title>Does Citrix Netscaler hasAuto Layer 7 HTTP DOS protection in 14.1?</title><link>https://community.stage.citrix.com/forums/topic/256614-does-citrix-netscaler-hasauto-layer-7-http-dos-protection-in-141/</link><description><![CDATA[<p>Hi Everyone.</p><p></p><p>Does Citrix Netscaler hasAuto Layer 7 HTTP DOS protection in 14.1?</p><p></p><p> I mean like auto threeshold based on statistics of the number of the requests seen or if the server starts returning 5xx (nginx returns 503 when the requests are too many) or responds slow.</p>]]></description><guid isPermaLink="false">256614</guid><pubDate>Mon, 23 Jun 2025 06:52:14 +0000</pubDate></item><item><title>what is AS_DEFAULT_DISPOSITION ?</title><link>https://community.stage.citrix.com/forums/topic/253741-what-is-as_default_disposition/</link><description><![CDATA[<p>
	Hi, 
</p>

<p>
	I was checking netscaler documents and lot of sections say "AS_DEFAULT_DISPOSITION". I couldnt able to find what is the meaning of this. 
</p>

<p>
	 
</p>

<p style="background-color:#ffffff;color:#000000;font-size:16px;padding:0px;text-align:left;">
	<b>XMLDoSAction</b><span> </span>One or more XML Denial-of-Service (XDoS) actions. Available settings function as follows:
</p>

<ul style="background-color:#ffffff;color:#000000;font-size:16px;padding:0px;text-align:left;">
	<li style="font-size:1rem;padding:0px;">
		Block - Block connections that violate this security check.
	</li>
	<li style="font-size:1rem;padding:0px;">
		Learn - Use the learning engine to generate a list of exceptions to this security check.
	</li>
	<li style="font-size:1rem;padding:0px;">
		Log - Log violations of this security check.
	</li>
	<li style="font-size:1rem;padding:0px;">
		Stats - Generate statistics for this security check.
	</li>
	<li style="font-size:1rem;padding:0px;">
		None - Disable all actions for this security check.
	</li>
</ul>

<p style="background-color:#ffffff;color:#000000;font-size:16px;padding:0px;text-align:left;">
	CLI users: To enable one or more actions, type “set appfw profile -XMLDoSAction” followed by the actions to be enabled. To turn off all actions, type “set appfw profile -XMLDoSAction none”. <span style="color:#e74c3c;"><strong>Default value: AS_DEFAULT_DISPOSITION</strong></span>
</p>
]]></description><guid isPermaLink="false">253741</guid><pubDate>Thu, 03 Apr 2025 06:53:55 +0000</pubDate></item><item><title>Default values for the appfw ?</title><link>https://community.stage.citrix.com/forums/topic/253740-default-values-for-the-appfw/</link><description><![CDATA[<p>
	hi, 
</p>

<p>
	I was looking for information about the appfw. I was reading the document and I checked that we have multiple options to configure the actions against the XML checks. The actions can be "None", Block", "Learn", "Log", Most of these actions are mentioned as optional. So my question is that if we dont configure these actions what would be the "default value" of the action?
</p>

<p>
	<img class="ipsImage ipsImage_thumbnailed" data-fileid="38248" width="676" alt="image.png.f54918c0f61367995ad0c12baf0f83e7.png" src="//media.invisioncic.com/r328636/monthly_2025_04/image.png.f54918c0f61367995ad0c12baf0f83e7.png" loading="lazy" height="425.88">
</p>
]]></description><guid isPermaLink="false">253740</guid><pubDate>Thu, 03 Apr 2025 06:32:38 +0000</pubDate></item><item><title>Safeguarding Against CVE-2025-24813 and CVE-2025-1974 using NetScaler WAF</title><link>https://community.stage.citrix.com/forums/topic/253744-safeguarding-against-cve-2025-24813-and-cve-2025-1974-using-netscaler-waf/</link><description><![CDATA[<p style="line-height:1.38;text-align:justify;">
	<span style="font-size:10.5pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#0e0e0e;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">In the ever-evolving landscape of cybersecurity, staying ahead of vulnerabilities is paramount. Two recent vulnerabilities, </span></span></span></span></span></span><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24813" style="text-decoration:none;" rel="external nofollow"><span style="font-size:10.5pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#1155cc;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:underline;"><span><span>CVE-2025-24813</span></span></span></span></span></span></span></span></a><span style="font-size:10.5pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#0e0e0e;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;"> and </span></span></span></span></span></span><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1974" style="text-decoration:none;" rel="external nofollow"><span style="font-size:10.5pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#1155cc;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:underline;"><span><span>CVE-2025-1974</span></span></span></span></span></span></span></span></a><span style="font-size:10.5pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#0e0e0e;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">, have raised significant concerns due to their potential for remote code execution (RCE) and information disclosure. Implementing robust security measures, such as Web Application Firewalls (WAFs) with tailored signatures, is crucial in mitigating these threats. </span></span></span></span></span></span><a href="https://www.netscaler.com/platform/web-application-firewall-waf" style="text-decoration:none;" rel="external nofollow"><span style="font-size:10.5pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#1155cc;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:underline;"><span><span>NetScaler WAF </span></span></span></span></span></span></span></span></a><span style="font-size:10.5pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#0e0e0e;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">once again has released signatures in record time to guard against these vulnerabilities.</span></span></span></span></span></span>
</p>

<p>
	 
</p>

<p style="line-height:1.38;">
	<span style="font-size:13pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#0e0e0e;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Understanding CVE-2025-24813</span></span></span></span></span></span>
</p>

<p>
	 
</p>

<p style="line-height:1.38;text-align:justify;">
	<span style="font-size:10.5pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#0e0e0e;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">CVE-2025-24813 </span></span></span></span></span></span><span style="font-size:10.5pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#0e0e0e;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">has a</span></span></span></span></span></span><span style="font-size:10.5pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#0e0e0e;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;"> CVSS 3.0 Score 9.8</span></span></span></span></span></span><span style="font-size:10.5pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#0e0e0e;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;"> is a path equivalence vulnerability in Apache Tomcat, a widely used open-source web server and servlet container. This flaw arises from improper handling of file paths containing internal dots (e.g., file.name), which, under specific conditions, can lead to unauthorized viewing of sensitive files, injection of malicious content, or even remote code execution. The vulnerability affects Apache Tomcat versions from 9.0.0.M1 through 9.0.98, 10.1.0-M1 through 10.1.34, and 11.0.0-M1 through 11.0.2.</span></span></span></span></span></span>
</p>

<p>
	 
</p>

<p style="line-height:1.38;">
	<span style="font-size:13pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#0e0e0e;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Understanding CVE-2025-1974</span></span></span></span></span></span>
</p>

<p>
	 
</p>

<p style="line-height:1.38;text-align:justify;">
	<span style="font-size:10.5pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#0e0e0e;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">CVE-2025-1974 </span></span></span></span></span></span><span style="font-size:10.5pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#0e0e0e;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">has a </span></span></span></span></span></span><span style="font-size:10.5pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#0e0e0e;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">CVSS 3.0 Score 9.8 </span></span></span></span></span></span><span style="font-size:10.5pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#0e0e0e;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">is a critical security vulnerability found in the ingress-nginx controller of Kubernetes, allows an unauthenticated attacker with access to the pod network to execute arbitrary code within the controller's context. This can result in unauthorized disclosure of sensitive information, including Secrets accessible to the controller. Successful exploitation can lead to control over the ingress-nginx controller pod. Due to the pod's often elevated privileges and access to cluster-wide secrets, an attacker could compromise the entire cluster, gain unauthorized data access, and move laterally within the environment.</span></span></span></span></span></span>
</p>

<p>
	<br />
	<br />
	 
</p>

<p style="line-height:1.38;">
	<span style="font-size:13pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#0e0e0e;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">NetScaler WAF signatures to the rescue</span></span></span></span></span></span>
</p>

<p>
	 
</p>

<p style="line-height:1.38;text-align:justify;">
	<span style="font-size:10.5pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#0e0e0e;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">NetScaler WAF serves as a critical line of defense against web-based threats by filtering and monitoring HTTP traffic between a web application and the internet. </span></span></span></span></span></span><a href="https://docs.netscaler.com/en-us/citrix-adc/current-release/application-firewall/signature-alerts/signature-update-version-150" style="text-decoration:none;" rel="external nofollow"><span style="font-size:10.5pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#1155cc;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:underline;"><span><span>NetScaler WAF signatures</span></span></span></span></span></span></span></span></a><span style="font-size:10.5pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#0e0e0e;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;"> were released in record time to detect and block exploit attempts targeting specific vulnerabilities like CVE-2025-24813 and CVE-2025-1974.</span></span></span></span></span></span>
</p>

<p style="line-height:1.38;text-align:justify;">
	<span style="font-size:10.5pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#0e0e0e;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">In order to make use of the signatures please </span></span></span></span></span></span><a href="https://docs.netscaler.com/en-us/citrix-adc/current-release/application-firewall/signatures/signature-auto-update.html" style="text-decoration:none;" rel="external nofollow"><span style="font-size:10.5pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#1155cc;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:underline;"><span><span>update</span></span></span></span></span></span></span></span></a><span style="font-size:10.5pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#0e0e0e;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;"> the signatures after making sure the NetScalers are connected to the internet. For networks where NetScalers can’t be exposed to the internet you can download the signatures </span></span></span></span></span></span><a href="https://docs.netscaler.com/en-us/citrix-adc/current-release/application-firewall/signatures/signature-auto-update.html" style="text-decoration:none;" rel="external nofollow"><span style="font-size:10.5pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#1155cc;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:underline;"><span><span>manually</span></span></span></span></span></span></span></span></a><span style="font-size:10.5pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#0e0e0e;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;"> and apply them very easily. To re-iterate, WAF signatures form a part of the hybrid security model of NetScaler and do not require customers to upgrade the firmware which enables a quick turnaround in dealing with such vulnerabilities. </span></span></span></span></span></span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#222222;"><span style="background-color:#ffffff;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Most of our customers who have recently renewed with UHMC or CPL licenses also get this capability on all their NetScaler instances.</span></span></span></span></span></span></span>
</p>

<p>
	 
</p>

<p style="line-height:1.38;text-align:justify;">
	<span style="font-size:10.5pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#0e0e0e;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">In conclusion, as cyber threats continue to evolve, maintaining a proactive security posture is essential. Vulnerabilities like CVE-2025-24813 and CVE-2025-1974 underscore the need for vigilant monitoring and robust defenses. Implementing and regularly updating WAF signatures tailored to these threats can significantly enhance your organization’s resilience against potential exploits.</span></span></span></span></span></span>
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">253744</guid><pubDate>Thu, 03 Apr 2025 19:32:29 +0000</pubDate></item><item><title>NetScaler WAF: Continued Focus on Developing Signatures for Common Vulnerability Exploits</title><link>https://community.stage.citrix.com/forums/topic/253689-netscaler-waf-continued-focus-on-developing-signatures-for-common-vulnerability-exploits/</link><description><![CDATA[<p style="line-height:1.38;">
	<span style="font-size:16pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Public Sans', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">NetScaler WAF Signatures - 2024</span></span></span></span></span></span>
</p>

<p>
	<br />
	 
</p>

<p style="line-height:1.38;">
	<span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;"> </span></span></span></span></span></span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">NetScaler WAF: Continued Focus on Developing Signatures for Common Vulnerability Exploits</span></span></span></span></span></span>
</p>

<p>
	 
</p>

<p style="line-height:1.38;">
	<span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">NetScaler WAF has a </span></span></span></span></span></span><a href="https://docs.netscaler.com/en-us/citrix-adc/current-release/application-firewall/signature-alerts/document-history.html" style="text-decoration:none;" rel="external nofollow"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#1155cc;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:underline;"><span><span>long history</span></span></span></span></span></span></span></span></a><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;"> of providing comprehensive protection against web application vulnerabilities. In 2024, we continue our focus on developing signatures for common vulnerability exploits.</span></span></span></span></span></span>
</p>

<p>
	 
</p>

<p style="line-height:1.38;">
	<span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Why is releasing signatures for CVE’s important?</span></span></span></span></span></span>
</p>

<p>
	 
</p>

<p style="line-height:1.38;">
	<span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Common vulnerability exploits are a major source of risk for web applications. Attackers are constantly looking for new ways to exploit these vulnerabilities, and it is important to have a web application firewall (WAF) that can block these attacks. Additionally, signatures prevent the need for upgrading NetScaler firmware to tackle CVE’s.</span></span></span></span></span></span>
</p>

<p>
	 
</p>

<p style="line-height:1.38;">
	<span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">How does NetScaler WAF protect against common vulnerability exploits?</span></span></span></span></span></span>
</p>

<p>
	 
</p>

<p style="line-height:1.38;">
	<span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">NetScaler WAF uses a variety of techniques to protect against common vulnerability exploits, including:</span></span></span></span></span></span>
</p>

<ul>
	<li style="list-style-type:disc;">
		<span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Signature-based detection:</span></span></span></span></span></span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;"> NetScaler WAF has a large database of signatures for common vulnerability exploits. These signatures can be used to identify and block attacks.</span></span></span></span></span></span>
	</li>
	<li style="list-style-type:disc;">
		<span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Heuristic detection:</span></span></span></span></span></span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;"> NetScaler WAF uses heuristic detection to identify and block attacks that are not covered by signatures.</span></span></span></span></span></span>
	</li>
</ul>

<p style="line-height:1.38;margin-top:16px;margin-bottom:16px;">
	<span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Continued Progress in 2024</span></span></span></span></span></span>
</p>

<p style="line-height:1.38;margin-top:16px;margin-bottom:16px;">
	<span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">In 2024, NetScaler released 181 signatures to protect against 146 CVEs, reducing the need for security administrators to create unique policies for common vulnerabilities. NetScaler maintains a consistent effort to release signatures regularly, as shown in the breakdown of signatures released throughout 2024.</span></span></span></span></span></span>
</p>

<p>
	 
</p>

<div>
	<table style="border:none;border-collapse:collapse;" width="932">
		<colgroup>
			<col width="233" />
			<col width="233" />
			<col width="233" />
			<col width="233" />
		</colgroup>
		<tbody>
			<tr>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Month</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Signature Versions released</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Total Signature rules</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Total CVE’s</span></span></span></span></span></span></span></span>
					</p>
				</td>
			</tr>
			<tr>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">2024-01</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">3</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">11</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">10</span></span></span></span></span></span></span></span>
					</p>
				</td>
			</tr>
			<tr>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">2024-02</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">2</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">16</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">14</span></span></span></span></span></span></span></span>
					</p>
				</td>
			</tr>
			<tr>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">2024-03</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">1</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">11</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">9</span></span></span></span></span></span></span></span>
					</p>
				</td>
			</tr>
			<tr>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">2024-04</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">2</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">23</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">19</span></span></span></span></span></span></span></span>
					</p>
				</td>
			</tr>
			<tr>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">2024-05</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">2</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">9</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">6</span></span></span></span></span></span></span></span>
					</p>
				</td>
			</tr>
			<tr>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">2024-06</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">2</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">14</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">14</span></span></span></span></span></span></span></span>
					</p>
				</td>
			</tr>
			<tr>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">2024-07</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">3</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">20</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">14</span></span></span></span></span></span></span></span>
					</p>
				</td>
			</tr>
			<tr>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">2024-08</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">1</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">10</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">8</span></span></span></span></span></span></span></span>
					</p>
				</td>
			</tr>
			<tr>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">2024-09</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">2</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">18</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">13</span></span></span></span></span></span></span></span>
					</p>
				</td>
			</tr>
			<tr>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">2024-10</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">2</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">25</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">20</span></span></span></span></span></span></span></span>
					</p>
				</td>
			</tr>
			<tr>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">2024-11</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">1</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">14</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">11</span></span></span></span></span></span></span></span>
					</p>
				</td>
			</tr>
			<tr>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">2024-12</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">1</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">10</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">8</span></span></span></span></span></span></span></span>
					</p>
				</td>
			</tr>
			<tr>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:10.5pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Roboto, sans-serif;"><span style="color:#172b4d;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Total</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">22</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">181</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #c1c7d0;vertical-align:top;padding:7px 11px 7px 11px;border-top:1px solid #c1c7d0;border-right:1px solid #c1c7d0;border-left:1px solid #c1c7d0;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">146</span></span></span></span></span></span></span></span>
					</p>
				</td>
			</tr>
		</tbody>
	</table>
</div>

<p>
	 
</p>

<p style="line-height:1.38;margin-top:16px;margin-bottom:16px;">
	<span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">NetScaler released signatures in 2024 to address high severity CVEs in several widely used products and services. Some of them are as follows:</span></span></span></span></span></span>
</p>

<p>
	 
</p>

<div>
	<table style="border:none;border-collapse:collapse;" width="932">
		<colgroup>
			<col width="233" />
			<col width="233" />
			<col width="233" />
			<col width="233" />
		</colgroup>
		<tbody>
			<tr>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">CVE</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">CVSS Score</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Impacted Service/Product</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">CVE Type</span></span></span></span></span></span></span></span>
					</p>
				</td>
			</tr>
			<tr>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23538" style="text-decoration:none;" rel="external nofollow"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#1155cc;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:underline;"><span><span>2024-23538</span></span></span></span></span></span></span></span></a></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">9.9</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Apache Fineract</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">SQL Injection</span></span></span></span></span></span></span></span>
					</p>
				</td>
			</tr>
			<tr>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46302" style="text-decoration:none;" rel="external nofollow"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#1155cc;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:underline;"><span><span>2024-46302</span></span></span></span></span></span></span></span></a></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">9.8</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Apache</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Deserialization of Untrusted Data Vulnerability</span></span></span></span></span></span></span></span>
					</p>
				</td>
			</tr>
			<tr>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1981" style="text-decoration:none;" rel="external nofollow"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#1155cc;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:underline;"><span><span>2024-1981</span></span></span></span></span></span></span></span></a></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">9.8</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Wordpress</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">SQL Injection</span></span></span></span></span></span></span></span>
					</p>
				</td>
			</tr>
			<tr>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40597" style="text-decoration:none;" rel="external nofollow"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Calibri, sans-serif;"><span style="color:#1155cc;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:underline;"><span><span>2023-40597</span></span></span></span></span></span></span></span></a></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">8.8</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Splunk Enterprise</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Absolute Path Traversal Vulnerability</span></span></span></span></span></span></span></span>
					</p>
				</td>
			</tr>
			<tr>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5204" style="text-decoration:none;" rel="external nofollow"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Calibri, sans-serif;"><span style="color:#1155cc;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:underline;"><span><span>2023-5204</span></span></span></span></span></span></span></span></a></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">8.8</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Wordpress (AI Chatbot)</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">SQL Injection</span></span></span></span></span></span></span></span>
					</p>
				</td>
			</tr>
			<tr>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46263" style="text-decoration:none;" rel="external nofollow"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Calibri, sans-serif;"><span style="color:#1155cc;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:underline;"><span><span>2023-46263</span></span></span></span></span></span></span></span></a></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">9.8</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Ivanti</span></span></span></span></span></span></span></span>
					</p>
				</td>
				<td style="border-bottom:1px solid #000000;vertical-align:top;padding:7px 7px 7px 7px;border-top:1px solid #000000;border-right:1px solid #000000;border-left:1px solid #000000;width:233px;">
					<p style="line-height:1.2;">
						<span><span><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Remote Code Execution</span></span></span></span></span></span></span></span>
					</p>
				</td>
			</tr>
		</tbody>
	</table>
</div>

<p>
	 
</p>

<p style="line-height:1.38;margin-top:16px;margin-bottom:16px;">
	<span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Commonly used products, including AI-based applications, are susceptible to attacks such as SQL Injection, as shown in the list above. NetScaler releases WAF signatures every two weeks to address these threats. It is recommended to stay informed about the latest signatures by subscribing to the signature update </span></span></span></span></span></span><a href="https://docs.netscaler.com/en-us/citrix-adc/current-release/application-firewall/signature-alerts.html" style="text-decoration:none;" rel="external nofollow"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#1155cc;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:underline;"><span><span>RSS Feeds</span></span></span></span></span></span></span></span></a><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">. You can find details about which CVEs have been addressed in recent updates in the signature update version documentation </span></span></span></span></span></span><a href="https://docs.netscaler.com/en-us/citrix-adc/current-release/application-firewall/signature-alerts/signature-update-version-145" style="text-decoration:none;" rel="external nofollow"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#1155cc;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:underline;"><span><span>here</span></span></span></span></span></span></span></span></a><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">.</span></span></span></span></span></span>
</p>

<p>
	 
</p>

<p style="line-height:1.38;">
	<span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">NetScaler offers comprehensive application security using signatures to protect application infrastructure. It also provides a deeper understanding of your application's security posture through Security Insights. Security Insights gives detailed analytics and reporting on potential threats, vulnerabilities, and attack patterns, allowing you to proactively identify and mitigate risks and you can configure WAF policies using Terraform/Ansible, refer to this </span></span></span></span></span></span><a href="https://community.stage.citrix.com/articles/automation/basic-application-protection-configuration-waf-using-terraform/" style="text-decoration:none;" rel=""><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#1155cc;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:underline;"><span><span>lab</span></span></span></span></span></span></span></span></a><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:Arial, sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;"> to learn more. This combination of signature-based protection and in-depth security insights and automation enables NetScaler to provide easy to use, robust and comprehensive application security.</span></span></span></span></span></span>
</p>

<p>
	<br />
	 
</p>
]]></description><guid isPermaLink="false">253689</guid><pubDate>Wed, 19 Mar 2025 18:47:54 +0000</pubDate></item><item><title>Question about HSTS and WAF</title><link>https://community.stage.citrix.com/forums/topic/252756-question-about-hsts-and-waf/</link><description><![CDATA[<p>
	Hello,
</p>

<p>
	I have a bit of a strange issue.  I <em>think</em> I understand what is going on, but not how to fix it.
</p>

<p>
	If I run my URL though SSLLabs, it tells me that Strict Transport Security (HSTS) is set to "no."
</p>

<p>
	However I have enabled HSTS using a rewrite action (and I also tried binding the options to my SSL virtual server).  If I run a 'curl' to the root of my application, I don't see the HSTS headers, and I get a "403 Forbidden" response.  If I run a 'curl' to a known static image or page behind my Netscaler, I get the image and the expected 'Strict-Transport-Security' headers.
</p>

<p>
	I assume what's happening is that my WAF is blocking access to "/" and therefore the rewrite action is never getting hit.  Is there a way that I can get SSLLabs to recognize HSTS?  Do I just need to set my WAF to allow access to "/"?
</p>

<p>
	Thanks!
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">252756</guid><pubDate>Mon, 18 Mar 2024 18:15:35 +0000</pubDate></item><item><title>How do you collect full body log WAF on Citrix ADC</title><link>https://community.stage.citrix.com/forums/topic/251495-how-do-you-collect-full-body-log-waf-on-citrix-adc/</link><description><![CDATA[<p>
	Hi team
</p>

<p>
	Do you know " how do you collect full body log WAF on Citrix ADC"
</p>

<p>
	I tried on Audit Message Action. But I don't know writen Expression collect full Body log?
</p>

<p>
	 
</p>

<p>
	Please help
</p>

<p>
	Thanks
</p>

<p>
	Hung Hoang
</p>
]]></description><guid isPermaLink="false">251495</guid><pubDate>Mon, 05 Jun 2023 15:30:00 +0000</pubDate></item><item><title>Bulk editing for learned rules regex</title><link>https://community.stage.citrix.com/forums/topic/253109-bulk-editing-for-learned-rules-regex/</link><description><![CDATA[<p>
	Greetings everybody,
</p>

<p>
	Looking for a way to edit the regex expression for all learned rules in a bulk rather than manually editing each learned rule before deploying it to relaxation.
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">253109</guid><pubDate>Wed, 24 Jul 2024 11:45:08 +0000</pubDate></item><item><title>Need to stop direct traversal attack with the help of WAF.</title><link>https://community.stage.citrix.com/forums/topic/253150-need-to-stop-direct-traversal-attack-with-the-help-of-waf/</link><description><![CDATA[<p>
	<span style="background-color:#ffffff;color:#0b1215;font-size:13px;">Need to stop direct traversal attack with the help of WAF. so many bad requests are hitting application server even though application in WAF. Need to stop the bad requests by using waf.</span>
</p>
]]></description><guid isPermaLink="false">253150</guid><pubDate>Fri, 09 Aug 2024 12:36:40 +0000</pubDate></item><item><title>Rate-Limiting with Bot Management type and Captcha mitigation</title><link>https://community.stage.citrix.com/forums/topic/253399-rate-limiting-with-bot-management-type-and-captcha-mitigation/</link><description><![CDATA[<p>
	Hello,
</p>

<p>
	I've been finding the documentation on the Bot Management to be very limiting  from Citrix.  I'm looking to implement rate-limiting for a specific application with a global based BOT policy.   For the rate-limit type I can do type: Session which the allows me to specify a specific cookie name to rate-limit off. If an application generates a cookie for each session lets call it "AppSession"  and each cookie for each client has a unique value .  Does the Netscaler itself track each session by the unique value of each individual client for the cookie specified in the policy?  Lets say for example i want to limit to no more than 2 requests over a 1 second interval.  In what scenarios would i specify a rate limit condition? If i wanted to narrow down to a specific url or other indicator?
</p>

<p>
	<a class="ipsAttachLink ipsAttachLink_image" href="//media.invisioncic.com/r328636/monthly_2024_11/Screenshot2024-11-07at11_25_58AM.png.208bd8beb4e63cb349cfe5db0357eea7.png" data-fileid="36654" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" data-fileid="36654" width="705" alt="Screenshot2024-11-07at11_25_58AM.thumb.png.b2e6a98e08024a3ccbe96d513033c0e9.png" src="//media.invisioncic.com/r328636/monthly_2024_11/Screenshot2024-11-07at11_25_58AM.thumb.png.b2e6a98e08024a3ccbe96d513033c0e9.png" loading="lazy" height="747.3"></a>
</p>

<p>
	Client
</p>

<p>
	 
</p>

<p>
	With regards to the captcha config on the bot management profile.  Is that just a spot where you configure the captcha service you want to use for mitigation  for say IP reputation? or does the netscaler itself perform the captcha?
</p>

<p>
	<a class="ipsAttachLink ipsAttachLink_image" href="//media.invisioncic.com/r328636/monthly_2024_11/Screenshot2024-11-07at11_32_49AM.png.5a3e521e19f1a3837a059436b6e605f9.png" data-fileid="36655" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" data-fileid="36655" width="739" alt="Screenshot2024-11-07at11_32_49AM.thumb.png.278efaae8a95976b4c02c09dbc2d68fd.png" src="//media.invisioncic.com/r328636/monthly_2024_11/Screenshot2024-11-07at11_32_49AM.thumb.png.278efaae8a95976b4c02c09dbc2d68fd.png" loading="lazy" height="746.39"></a>
</p>

<p>
	Thanks,
</p>
]]></description><guid isPermaLink="false">253399</guid><pubDate>Thu, 07 Nov 2024 17:34:23 +0000</pubDate></item><item><title>Citrix Bot management -  Default Bot Signature versions different in HA pair.  Secondary will not upgrade from Base version 18 to 19</title><link>https://community.stage.citrix.com/forums/topic/253392-citrix-bot-management-default-bot-signature-versions-different-in-ha-pair-secondary-will-not-upgrade-from-base-version-18-to-19/</link><description><![CDATA[<p>
	I have an HA pair of netscalers running 13.1 code that seems to be having issues with the Bot signature download.   The feature is enabled on both appliances, but my primary has a base version of 19. My secondary has a base version of 18.  I have forced sync from the Primary to the secondary with success.   When I attempt to do the signature update from the secondary appliance I receive the following message:<br />
	<br />
	&gt; update bot signature "*Default Bot Signatures"<br />
	ERROR: The command was ignored.
</p>

<p>
	Auto-update is configure on both appliances in the HA.  The /var/log/bot_auto_update.log shows:<br />
	2024-11-06 13:00:04,605 DEBUG Both pre and post SHA is same..<br />
	2024-11-06 13:00:04,605 DEBUG Default Bot Signatures are upto date
</p>

<p>
	The var/log/ns.log file shows the same error message:<br />
	Command "update bot signature "*Default Bot Signatures"" - Status "ERROR: The command was ignored."
</p>

<p>
	As a last ditch resort I've copied the following files and folders from the primary to the standby unit and reloaded the standby unit:
</p>

<p>
	/nsconfig/bot_signatures/  -  I copied the whole bot_signatures folder to the standby appliance after removing the old folder<br />
	/netscaler/default_bot_id<br />
	/netscaler/default_bot_signatures.json<br />
	/netscaler/default_bot_signatures.schema
</p>

<p>
	Even after copying these files from the primary to the standby manually I have yet to be able to get this to update to the base version of 19 for Bot signatures.
</p>

<p>
	Heres the output from the appliances:<br />
	Primary:<br />
	&gt; show bot signature<br />
	1)      Url: default_bot_signatures.json        Name: "*Default Bot Signatures"<br />
	        Creation Date: Wed Sep 18 10:00:07 2024<br />
	        Base Version: "19"      <strong>Size: 811064 bytes</strong>
</p>

<p>
	Total signature Size:   0 bytes<br />
	Total Import Size:      2612024 bytes<br />
	 Done
</p>

<p>
	Standby:<br />
	&gt; show bot signature<br />
	1)      Url: default_bot_signatures.json        Name: "*Default Bot Signatures"<br />
	        Creation Date: Thu Aug  1 10:00:10 2024<br />
	        Base Version: "18"      <strong>Size: 820026 bytes</strong>
</p>

<p>
	Total signature Size:   0 bytes<br />
	Total Import Size:      2612024 bytes<br />
	 Done
</p>

<p>
	Is there another spot I should be looking for the default_bot_signatures.json?
</p>
]]></description><guid isPermaLink="false">253392</guid><pubDate>Wed, 06 Nov 2024 13:52:14 +0000</pubDate></item><item><title>Application is not loading properly and not working properly through WAF profile.</title><link>https://community.stage.citrix.com/forums/topic/253147-application-is-not-loading-properly-and-not-working-properly-through-waf-profile/</link><description><![CDATA[<p>
	Dear Sir,
</p>

<p>
	Greetings of the day!
</p>

<p>
	 
</p>

<p>
	Application is not loading properly and not working properly through WAF profile. Application gives a blank page after multiple refreshes of the browser. Checked it in the incognito browser and a different browser. it's showing the same behavior.
</p>

<p>
	Even  after removing block mode also the app is not working but <strong>If we unbind the WAF policy and everything started working as expected.</strong>
</p>

<p>
	Citrix suggested that unblock the<strong> Malformed request action.</strong>
</p>

<p>
	Unblocking the Malformed request action is not good idea as per my knowledge. If we unblock the Malformed request action, then impact will be bad for another working WAF profiles why because we are allowing malformed requests as per your request.
</p>

<p>
	Please provide any other solution to fix the issue?
</p>

<p>
	 
</p>

<p>
	Regards,
</p>

<p>
	Rajkumar M
</p>
]]></description><guid isPermaLink="false">253147</guid><pubDate>Fri, 09 Aug 2024 11:25:16 +0000</pubDate></item><item><title>Default WAF Profiles using which API Spec?</title><link>https://community.stage.citrix.com/forums/topic/253053-default-waf-profiles-using-which-api-spec/</link><description><![CDATA[<p>
	Hi,<br>
	<br>
	I'm a bit confused and was not able to find a documentation on the mapping of the WAF Protection to the actual WAF Profile (or API Spec) used.
</p>

<p>
	Does anybody now?
</p>

<p>
	<img class="ipsImage ipsImage_thumbnailed" data-fileid="35318" width="671" alt="image.png.84fdff670d805f39777845fc53c46e23.png" src="//media.invisioncic.com/r328636/monthly_2024_07/image.png.84fdff670d805f39777845fc53c46e23.png" loading="lazy" height="469.7">
</p>

<p>
	<a class="ipsAttachLink ipsAttachLink_image" href="//media.invisioncic.com/r328636/monthly_2024_07/image.png.ba4500aad2a6ed4b6c632add34a84f1e.png" data-fileid="35319" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" data-fileid="35319" width="1000" alt="image.thumb.png.9b6664d51a5d46ca39d4c4b09014438b.png" src="//media.invisioncic.com/r328636/monthly_2024_07/image.thumb.png.9b6664d51a5d46ca39d4c4b09014438b.png" loading="lazy" height="260"></a>
</p>

<p>
	 
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">253053</guid><pubDate>Wed, 03 Jul 2024 09:54:47 +0000</pubDate></item><item><title>relaxation - html xss - ignore domain and permit based on path</title><link>https://community.stage.citrix.com/forums/topic/250553-relaxation-html-xss-ignore-domain-and-permit-based-on-path/</link><description><![CDATA[<p>
	Hi,
</p>

<p>
	 
</p>

<p>
	we are currently implementing / finetuning the WAF setup.
</p>

<p>
	we are hosting the same website for hundreds of customers, each customer with his own domain.
</p>

<p>
	 
</p>

<p>
	I'm a bit stuck on implementing relaxation rules, define something which always works, regardless the domain of the url.
</p>

<p>
	 
</p>

<p>
	An example of the error I get:
</p>

<p>
	CEF:0|Citrix|NetScaler|NS13.0|APPFW|APPFW_XSS|6|src=1.2.3.4 spt=13771 method=POST request=https://domain/Profile/MyProfile msg=Cross-site script check failed for field __eventtarget\="Bad tag: %# 
</p>

<p>
	=&gt; this is blocked and I would like to create a relaxation rule for this.
</p>

<p>
	This should ignore the domain part of the url and only look ath the path part
</p>

<p>
	so
</p>

<p>
	<a href="https://customer.domain.net/Profile/MyProfile" rel="external nofollow">https://customer.domain.net/Profile/MyProfile</a> - field __eventtarget should be allowed
</p>

<p>
	<a href="https://domaincustomer.com/Profile/MyProfile" rel="external nofollow">https://domaincustomer.com/Profile/MyProfile</a> - field __eventtarget should be allowed
</p>

<p>
	 
</p>

<p>
	in responder policies I can use the variable HTTP.REQ.URL.PATH but can I use something similar in regex expressions in a situation like this?
</p>

<p>
	 
</p>

<p>
	thanks for your help!
</p>

<p>
	 
</p>

<p>
	Gijs.
</p>
]]></description><guid isPermaLink="false">250553</guid><pubDate>Wed, 11 Jan 2023 15:20:31 +0000</pubDate></item></channel></rss>
