First published: Sat May 30 2015(Updated: )
The WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 does not send a restrictive X-Frame-Options HTTP header, which allows remote attackers to conduct clickjacking attacks via vectors involving an IFRAME element.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bluecoat Ssl Visibility Appliance Sv800 Firmware | <=3.8.3 | |
Broadcom SSL Visibility Appliance | ||
Broadcom SSL Visibility Appliance | <=3.8.3 | |
Blue Coat SSL Visibility Appliance SV1800 Firmware | ||
Blue Coat SSL Visibility Appliance SV2800 | <=3.8.3 | |
Blue Coat SSL Visibility Appliance SV2800 Firmware | ||
Broadcom SSL Visibility Appliance | <=3.8.3 | |
Blue Coat SSL Visibility Appliance SV3800 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2854 has been assigned a medium severity level due to its potential to enable clickjacking attacks.
Fix CVE-2015-2854 by updating the Blue Coat SSL Visibility Appliance to version 3.8.4 or later.
CVE-2015-2854 affects the Blue Coat SSL Visibility Appliance models SV800, SV1800, SV2800, and SV3800 running firmware versions 3.6.x through 3.8.3.
Yes, CVE-2015-2854 can be exploited by remote attackers to conduct clickjacking attacks via IFRAME elements.
The absence of the X-Frame-Options header in CVE-2015-2854 allows malicious sites to embed the vulnerable web application in a frame, leading to potential user interaction without their knowledge.