CVE-2008-4515
Blue Coat K9 Web Protection 4.0.230 Beta relies on client-side JavaScript as a protection mechanism, which allows remote attackers to bypass authentication and access the (1) summary, (2) detail, (3) overrides, and (4) pwemail pages by disabling…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.56%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Blue Coat K9 Web Protection 4.0.230 Beta relies on client-side JavaScript as a protection mechanism, which allows remote attackers to bypass authentication and access the (1) summary, (2) detail, (3) overrides, and (4) pwemail pages by disabling JavaScript.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.56% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- blue coat systems/k9 web protection
- Source
- cve@mitre.org
References
- http://dicas3000.blogspot.com/2008/10/blue-coat-k9-web-protection-v40230-beta.html
- http://seclists.org/fulldisclosure/2008/Oct/0070.html
- http://www.securityfocus.com/bid/31584
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45696
- http://dicas3000.blogspot.com/2008/10/blue-coat-k9-web-protection-v40230-beta.html
- http://seclists.org/fulldisclosure/2008/Oct/0070.html
- http://www.securityfocus.com/bid/31584
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45696
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.