First published: Wed Oct 08 2008(Updated: )
Cross-site scripting (XSS) vulnerability in the ICAP patience page in Blue Coat Security Gateway OS (SGOS) 4.2 before 4.2.9, 5.2 before 5.2.5, and 5.3 before 5.3.1.7 allows remote attackers to inject arbitrary web script or HTML via the URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bluecoat Security Gateway OS | =4.2 | |
Bluecoat Security Gateway OS | =5.2 | |
Bluecoat Security Gateway OS | =5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4485 has a medium severity rating due to its potential for enabling cross-site scripting attacks.
The fix for CVE-2008-4485 involves upgrading to Blue Coat Security Gateway OS versions 4.2.9, 5.2.5, or 5.3.1.7 or later for vulnerability mitigation.
CVE-2008-4485 affects Blue Coat Security Gateway OS versions 4.2 prior to 4.2.9, 5.2 prior to 5.2.5, and 5.3 prior to 5.3.1.7.
CVE-2008-4485 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.
CVE-2008-4485 can be exploited by remote attackers targeting affected versions of the Blue Coat Security Gateway OS.