PT-2008-5748 · Blue Coat · Blue Coat K9 Web Protection
Published
2008-10-09
·
Updated
2017-08-08
·
CVE-2008-4515
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Blue Coat K9 Web Protection version 4.0.230 Beta
Description:
The issue allows remote attackers to bypass authentication and access certain pages by disabling JavaScript, as the software relies on client-side JavaScript as a protection mechanism. This enables access to the summary, detail, overrides, and pwemail pages.
Recommendations:
For Blue Coat K9 Web Protection version 4.0.230 Beta, consider implementing server-side authentication mechanisms to prevent bypassing authentication by disabling JavaScript. As a temporary workaround, restrict access to the summary, detail, overrides, and pwemail pages until a more secure authentication mechanism is in place.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Blue Coat K9 Web Protection