Lucene search

K
cveMitreCVE-2009-1211
HistoryApr 01, 2009 - 10:30 a.m.

CVE-2009-1211

2009-04-0110:30:00
CWE-16
mitre
web.nvd.nist.gov
30
blue coat
proxysg
access controls
bypass
security vulnerability
http host header
cve-2009-1211

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.001

Percentile

51.5%

Blue Coat ProxySG, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.

Affected configurations

Nvd
Node
bluecoatproxysg_va-10
OR
bluecoatproxysg_va-15
OR
bluecoatproxysg_va-20
OR
bluecoatproxysg_va-5
OR
bluecoatproxysg
OR
bluecoatproxysg_sg210-10Match--acceleration
OR
bluecoatproxysg_sg210-10Match--full_proxy
OR
bluecoatproxysg_sg210-25Match--acceleration
OR
bluecoatproxysg_sg210-25Match--full_proxy
OR
bluecoatproxysg_sg210-5Match--acceleration
OR
bluecoatproxysg_sg210-5Match--full_proxy
OR
bluecoatproxysg_sg510-10Match--acceleration
OR
bluecoatproxysg_sg510-10Match--full_proxy
OR
bluecoatproxysg_sg510-20Match--acceleration
OR
bluecoatproxysg_sg510-20Match--full_proxy
OR
bluecoatproxysg_sg510-25Match--acceleration
OR
bluecoatproxysg_sg510-25Match--full_proxy
OR
bluecoatproxysg_sg510-5Match--full_proxy
OR
bluecoatproxysg_sg810-10Match--acceleration
OR
bluecoatproxysg_sg810-10Match--full_proxy
OR
bluecoatproxysg_sg810-20Match--acceleration
OR
bluecoatproxysg_sg810-20Match--full_proxy
OR
bluecoatproxysg_sg810-25Match--acceleration
OR
bluecoatproxysg_sg810-25Match--full_proxy
OR
bluecoatproxysg_sg810-5Match--full_proxy
OR
bluecoatproxysg_sg9000-10Match--acceleration
OR
bluecoatproxysg_sg9000-10Match--full_proxy
OR
bluecoatproxysg_sg9000-20Match--acceleration
OR
bluecoatproxysg_sg9000-20Match--full_proxy
OR
bluecoatproxysg_sg9000-5Match--acceleration
OR
bluecoatproxysg_sg9000-5Match--full_proxy
VendorProductVersionCPE
bluecoatproxysg_va-10*cpe:2.3:a:bluecoat:proxysg_va-10:*:*:*:*:*:*:*:*
bluecoatproxysg_va-15*cpe:2.3:a:bluecoat:proxysg_va-15:*:*:*:*:*:*:*:*
bluecoatproxysg_va-20*cpe:2.3:a:bluecoat:proxysg_va-20:*:*:*:*:*:*:*:*
bluecoatproxysg_va-5*cpe:2.3:a:bluecoat:proxysg_va-5:*:*:*:*:*:*:*:*
bluecoatproxysg*cpe:2.3:h:bluecoat:proxysg:*:*:*:*:*:*:*:*
bluecoatproxysg_sg210-10-cpe:2.3:h:bluecoat:proxysg_sg210-10:-:-:acceleration:*:*:*:*:*
bluecoatproxysg_sg210-10-cpe:2.3:h:bluecoat:proxysg_sg210-10:-:-:full_proxy:*:*:*:*:*
bluecoatproxysg_sg210-25-cpe:2.3:h:bluecoat:proxysg_sg210-25:-:-:acceleration:*:*:*:*:*
bluecoatproxysg_sg210-25-cpe:2.3:h:bluecoat:proxysg_sg210-25:-:-:full_proxy:*:*:*:*:*
bluecoatproxysg_sg210-5-cpe:2.3:h:bluecoat:proxysg_sg210-5:-:-:acceleration:*:*:*:*:*
Rows per page:
1-10 of 311

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.001

Percentile

51.5%

Related for CVE-2009-1211