PT-2008-5748 · Blue Coat · Blue Coat K9 Web Protection
Publicado
2008-10-09
·
Atualizado
2017-08-08
·
CVE-2008-4515
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Blue Coat K9 Web Protection version 4.0.230 Beta
Description:
The issue allows remote attackers to bypass authentication and access certain pages by disabling JavaScript, as the software relies on client-side JavaScript as a protection mechanism. This enables access to the summary, detail, overrides, and pwemail pages.
Recommendations:
For Blue Coat K9 Web Protection version 4.0.230 Beta, consider implementing server-side authentication mechanisms to prevent bypassing authentication by disabling JavaScript. As a temporary workaround, restrict access to the summary, detail, overrides, and pwemail pages until a more secure authentication mechanism is in place.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Blue Coat K9 Web Protection