CVE-2015-1454
https://notcve.org/view.php?id=CVE-2015-1454
Blue Coat ProxyClient before 3.3.3.3 and 3.4.x before 3.4.4.10 and Unified Agent before 4.1.3.151952 does not properly validate certain certificates, which allows man-in-the-middle attackers to spoof ProxySG Client Managers, and consequently modify configurations and execute arbitrary software updates, via a crafted certificate. Blue Coat ProxyClient anterior a 3.3.3.3 y 3.4.x anterior a 3.4.4.10 y Unified Agent anterior a 4.1.3.151952 no validan correctamente ciertos certificados, lo que permite a atacantes man-in-the-middle falsificar los gestores de clientes del proxy SG (ProxySG Client Managers), y como consecuencia modificar las configuraciones y ejecutar actualizaciones de software arbitrarias, a través de un certificado manipulado. • http://secunia.com/advisories/62617 https://bto.bluecoat.com/security-advisory/sa89 • CWE-310: Cryptographic Issues •
CVE-2014-2565
https://notcve.org/view.php?id=CVE-2014-2565
The commandline interface in Blue Coat Content Analysis System (CAS) 1.1 before 1.1.4.2 allows remote administrators to execute arbitrary commands via unspecified vectors, related to "command injection." La interfaz commandline en Blue Coat Content Analysis System (CAS) 1.1 anterior a 1.1.4.2 permite a administradores remotos ejecutar comandos arbitrarios a través de vectores no especificados, relacionado con "inyección de comandos." • https://kb.bluecoat.com/index?page=content&id=SA78&actp=LIST • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2014-2033
https://notcve.org/view.php?id=CVE-2014-2033
The caching feature in SGOS in Blue Coat ProxySG 5.5 through 5.5.11.3, 6.1 through 6.1.6.3, 6.2 through 6.2.15.3, 6.4 through 6.4.6.1, and 6.3 and 6.5 before 6.5.4 allows remote authenticated users to bypass intended access restrictions during a time window after account deletion or modification by leveraging knowledge of previously valid credentials. La funcionalidad de cacheo en SGOS en Blue Coat ProxySG 5.5 hasta 5.5.11.3, 6.1 hasta 6.1.6.3, 6.2 hasta 6.2.15.3, 6.4 hasta 6.4.6.1 y 6.3 y 6.5 anterior a 6.5.4 permite a usuarios remotos autenticados evadir restricciones de acceso durante una ventana de tiempo después del borrado o modificación de cuenta mediante el aprovechamiento de conocimiento de credenciales anteriormente validos. • http://www.kb.cert.org/vuls/id/221620 https://kb.bluecoat.com/index?page=content&id=SA77 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2013-5959
https://notcve.org/view.php?id=CVE-2013-5959
Blue Coat ProxySG before 6.2.14.1, 6.3.x, 6.4.x, and 6.5 before 6.5.2 allows remote attackers to cause a denial of service (memory consumption and dropped connections) via a recursive href in an HTML page, which triggers a large number of HTTP RW pipeline pre-fetch requests. Blue Coat ProxySG anteriores a 6.2.14.1, 6.3.x, 6.4.x, y 6.5 (anteriores a 6.5.2) permite a atacantes remotos causar una denegación de servicio (consumo de memoria y conexiones interrumpidas) a través de un href recursivo en una página HTML, lo que dispara un número elevado de peticiones pipeline pre-fetch HTTP RW. • http://osvdb.org/97767 http://secunia.com/advisories/54991 http://www.securitytracker.com/id/1029088 https://kb.bluecoat.com/index?page=content&id=SA75 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2010-5190
https://notcve.org/view.php?id=CVE-2010-5190
The Active Content Transformation functionality in Blue Coat ProxySG before SGOS 4.3.4.2, 5.x before SGOS 5.4.5.1, 5.5 before SGOS 5.5.4.1, and 6.x before SGOS 6.1.2.1 allows remote attackers to bypass JavaScript detection via HTML entities. La funcionalidad Active Content Transformation en Blue Coat ProxySG anterior a SGOS v4.3.4.2, v5.x anterior a SGOS v5.4.5.1, v5.5 anterior a SGOS v5.5.4.1, y v6.x anterior a SGOS v6.1.2.1 permite a atacantes remotos saltarse la detección JavaScript a través de entidades HTML. • https://kb.bluecoat.com/index?page=content&id=SA48 • CWE-264: Permissions, Privileges, and Access Controls •