First published: Sat May 30 2015(Updated: )
The WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 does not include the HTTPOnly flag in a Set-Cookie header for the administrator's cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, a different vulnerability than CVE-2015-2855.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom SSL Visibility Appliance | <=3.8.3 | |
Blue Coat SSL Visibility Appliance SV1800 Firmware | ||
Bluecoat Ssl Visibility Appliance Sv800 Firmware | <=3.8.3 | |
Broadcom SSL Visibility Appliance | ||
Broadcom SSL Visibility Appliance | <=3.8.3 | |
Blue Coat SSL Visibility Appliance SV3800 Firmware | ||
Blue Coat SSL Visibility Appliance SV2800 | <=3.8.3 | |
Blue Coat SSL Visibility Appliance SV2800 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4138 is considered a medium severity vulnerability due to its potential exploitation by remote attackers.
To fix CVE-2015-4138, update the Blue Coat SSL Visibility Appliance firmware to version 3.8.4 or later.
CVE-2015-4138 affects Blue Coat SSL Visibility Appliances, specifically models SV800, SV1800, SV2800, and SV3800 running firmware versions from 3.6.x to 3.8.3.
Not addressing CVE-2015-4138 could allow attackers to steal session cookies, potentially granting unauthorized access to sensitive information.
Yes, CVE-2015-4138 is related to cookie security as it involves the absence of the HTTPOnly flag, which protects cookies from theft via client-side scripts.