PT-2008-5748 · Blue Coat · Blue Coat K9 Web Protection

Published

2008-10-09

·

Updated

2017-08-08

·

CVE-2008-4515

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Blue Coat K9 Web Protection version 4.0.230 Beta
Description: The issue allows remote attackers to bypass authentication and access certain pages by disabling JavaScript, as the software relies on client-side JavaScript as a protection mechanism. This enables access to the summary, detail, overrides, and pwemail pages.
Recommendations: For Blue Coat K9 Web Protection version 4.0.230 Beta, consider implementing server-side authentication mechanisms to prevent bypassing authentication by disabling JavaScript. As a temporary workaround, restrict access to the summary, detail, overrides, and pwemail pages until a more secure authentication mechanism is in place.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-4515

Affected Products

Blue Coat K9 Web Protection