CVE-2015-4138: Infoleak
The WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 does not include the HTTPOnly flag in a Set-Cookie header for the administrator's cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, a different vulnerability than CVE-2015-2855.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4138?
CVE-2015-4138 is considered a medium severity vulnerability due to its potential exploitation by remote attackers.
How do I fix CVE-2015-4138?
To fix CVE-2015-4138, update the Blue Coat SSL Visibility Appliance firmware to version 3.8.4 or later.
What systems are affected by CVE-2015-4138?
CVE-2015-4138 affects Blue Coat SSL Visibility Appliances, specifically models SV800, SV1800, SV2800, and SV3800 running firmware versions from 3.6.x to 3.8.3.
What is the risk of not addressing CVE-2015-4138?
Not addressing CVE-2015-4138 could allow attackers to steal session cookies, potentially granting unauthorized access to sensitive information.
Is CVE-2015-4138 related to cookie security?
Yes, CVE-2015-4138 is related to cookie security as it involves the absence of the HTTPOnly flag, which protects cookies from theft via client-side scripts.