CVE-2015-2853
Published May 30, 2015
Last updated 8 years ago
Overview
- Description
- Session fixation vulnerability in the WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 allows remote attackers to hijack web sessions by providing a session ID.
- Source
- cret@cert.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Evaluator
- Comment
- <a href="http://cwe.mitre.org/data/definitions/384.html">CWE-384: Session Fixation</a>
- Impact
- -
- Solution
- -
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:blue_coat:ssl_visibility_appliance_sv3800_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "33E52942-0C82-472D-8065-8D33221285EE", "versionEndIncluding": "3.8.3" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:blue_coat:ssl_visibility_appliance_sv3800:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "E7CA4AEA-C309-4E96-8835-CADB7FA32C05" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:blue_coat:ssl_visibility_appliance_sv2800_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "041A6762-C233-4163-8692-4DE054F1C9EE", "versionEndIncluding": "3.8.3" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:blue_coat:ssl_visibility_appliance_sv2800:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "A6B04FC6-F165-4590-B088-7F126667ACD3" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:blue_coat:ssl_visibility_appliance_sv1800_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "658F9B38-DA76-4CF8-961C-DCD596DEC697", "versionEndIncluding": "3.8.3" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:blue_coat:ssl_visibility_appliance_sv1800:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F280A1EE-FEB6-435E-B566-132E9C2F54C2" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:blue_coat:ssl_visibility_appliance_sv800_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6A543761-A119-465D-A249-47347CE5EED9", "versionEndIncluding": "3.8.3" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:blue_coat:ssl_visibility_appliance_sv800:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "EB72CFF6-C8B6-429C-A036-2560CAE3C713" } ], "operator": "OR" } ], "operator": "AND" } ]