CVE-2015-2853

Session fixation vulnerability in the WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 allows remote attackers to hijack web sessions by providing a session ID.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
blue_coatssl_visibility_appliance_sv3800_firmware
𝑥
≤ 3.8.3
blue_coatssl_visibility_appliance_sv2800_firmware
𝑥
≤ 3.8.3
blue_coatssl_visibility_appliance_sv1800_firmware
𝑥
≤ 3.8.3
blue_coatssl_visibility_appliance_sv800_firmware
𝑥
≤ 3.8.3
𝑥
= Vulnerable software versions