Authentication Flaw in Blue Coat ProxySG Affects Upstream Origin Content Servers
CVE-2015-4334
Currently unrated
Summary
The default configuration of Blue Coat ProxySG in versions prior to 6.2.16.5, 6.5 prior to 6.5.7.1, and 6.6 prior to 6.6.2.1 allows for unintended forwarding of authentication challenges from upstream origin content servers during explicit proxy operations. This misconfiguration could enable remote attackers to leverage the 407 Proxy Authentication Required response to extract sensitive information, particularly when NTLM authentication is utilized. This presents a significant risk, emphasizing the need for careful configuration management and security practices.
References
Timeline
Vulnerability published
Vulnerability Reserved