CVE-2015-4138
Published May 30, 2015
Last updated 9 years ago
Overview
- Description
- The WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 does not include the HTTPOnly flag in a Set-Cookie header for the administrator's cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, a different vulnerability than CVE-2015-2855.
- Source
- cret@cert.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-200
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:blue_coat:ssl_visibility_appliance_sv1800_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "658F9B38-DA76-4CF8-961C-DCD596DEC697", "versionEndIncluding": "3.8.3" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:blue_coat:ssl_visibility_appliance_sv1800:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F280A1EE-FEB6-435E-B566-132E9C2F54C2" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:blue_coat:ssl_visibility_appliance_sv800_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6A543761-A119-465D-A249-47347CE5EED9", "versionEndIncluding": "3.8.3" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:blue_coat:ssl_visibility_appliance_sv800:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "EB72CFF6-C8B6-429C-A036-2560CAE3C713" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:blue_coat:ssl_visibility_appliance_sv3800_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "33E52942-0C82-472D-8065-8D33221285EE", "versionEndIncluding": "3.8.3" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:blue_coat:ssl_visibility_appliance_sv3800:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "E7CA4AEA-C309-4E96-8835-CADB7FA32C05" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:blue_coat:ssl_visibility_appliance_sv2800_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "041A6762-C233-4163-8692-4DE054F1C9EE", "versionEndIncluding": "3.8.3" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:blue_coat:ssl_visibility_appliance_sv2800:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "A6B04FC6-F165-4590-B088-7F126667ACD3" } ], "operator": "OR" } ], "operator": "AND" } ]