CVE-2015-4138 Information
Feb 14, 2021
cve
Description
The WebUI component in Blue Coat SSL Visibility Appliance SV800 SV1800 SV2800 and SV3800 3.6.x through 3.8.x before 3.8.4 does not include the HTTPOnly flag in a Set-Cookie header for the administrator’s cookie which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie a different vulnerability than CVE-2015-2855.
Reference
http://www.kb.cert.org/vuls/id/498348 https://bto.bluecoat.com/security-advisory/sa96
Share on: