PT-2016-3928 · Blue Coat · Blue Coat Proxysg+1

Published

2016-01-08

·

Updated

2016-01-13

·

CVE-2015-8597

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Blue Coat ProxySG versions 6.5 through 6.5.8.8 Blue Coat ProxySG version 6.6 Advanced Secure Gateway (ASG) version 6.6
Description The issue allows remote attackers to redirect users to arbitrary web sites, potentially leading to phishing attacks. This can be achieved via a base64-encoded URL in conjunction with a "clear text" one in a coaching page. For example, an attacker could use a URL like "http://www.%humbug-URL%.local/bluecoat-splash-API?%BASE64-URL%."
Recommendations For Blue Coat ProxySG versions 6.5 through 6.5.8.8, update to version 6.5.8.8 or later. For Blue Coat ProxySG version 6.6 and Advanced Secure Gateway (ASG) version 6.6, consider disabling the coaching page feature until a patch is available. As a temporary workaround, restrict access to the coaching page to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2015-8597

Affected Products

Advanced Secure Gateway
Blue Coat Proxysg