CVE-2015-0938: Infoleak
search.php on the Blue Coat Malware Analysis appliance with software before 4.2.4.20150312-RELEASE allows remote attackers to bypass intended access restrictions, and list or read arbitrary documents, by providing matching keywords in conjunction with a crafted parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0938?
CVE-2015-0938 has been rated as a moderate severity vulnerability due to its ability to allow unauthorized access to sensitive documents.
How do I fix CVE-2015-0938?
To fix CVE-2015-0938, upgrade the Blue Coat Malware Analysis appliance to version 4.2.4.20150312-RELEASE or later.
What systems are affected by CVE-2015-0938?
CVE-2015-0938 affects Blue Coat Malware Analysis appliances running software versions prior to 4.2.4.20150312-RELEASE.
What type of attack can be performed using CVE-2015-0938?
CVE-2015-0938 allows remote attackers to bypass access restrictions and read arbitrary documents by exploiting crafted parameters.
Is authentication required to exploit CVE-2015-0938?
No, CVE-2015-0938 can be exploited by remote attackers without having to authenticate.