CVE-2015-2854: Input Validation
The WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 does not send a restrictive X-Frame-Options HTTP header, which allows remote attackers to conduct clickjacking attacks via vectors involving an IFRAME element.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2854?
CVE-2015-2854 has been assigned a medium severity level due to its potential to enable clickjacking attacks.
How do I fix CVE-2015-2854?
Fix CVE-2015-2854 by updating the Blue Coat SSL Visibility Appliance to version 3.8.4 or later.
Which products are affected by CVE-2015-2854?
CVE-2015-2854 affects the Blue Coat SSL Visibility Appliance models SV800, SV1800, SV2800, and SV3800 running firmware versions 3.6.x through 3.8.3.
Can CVE-2015-2854 be exploited remotely?
Yes, CVE-2015-2854 can be exploited by remote attackers to conduct clickjacking attacks via IFRAME elements.
What does the lack of the X-Frame-Options header mean in CVE-2015-2854?
The absence of the X-Frame-Options header in CVE-2015-2854 allows malicious sites to embed the vulnerable web application in a frame, leading to potential user interaction without their knowledge.