Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The default configuration of SGOS in Blue Coat ProxySG before 6.2.16.5, 6.5 before 6.5.7.1, and 6.6 before 6.6.2.1 forwards authentication challenges from upstream origin content servers (OCS) when used in an explicit proxy deployment, which makes it easier for remote attackers to obtain sensitive information via a 407 (aka Proxy Authentication Required) HTTP status code, as demonstrated when using NTLM authentication.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Blue Coat Systems ProxySG SGOS 安全漏洞
Vulnerability Description
Blue Coat Systems ProxySG是美国Blue Coat Systems公司的一套安全Web网关设备。该设备提供了用户验证、Web过滤、数据丢失保护等功能,以控制所有的Web流量。 Blue Coat Systems ProxySG中的SGOS的默认配置中存在安全漏洞,该漏洞源于当程序在显式的代理服务器部署中使用时,会前向转发来自上游的origin content servers(OCS)服务器的身份验证质询。远程攻击者可借助407 HTTP状态码利用该漏洞获取敏感信息。以下版本受到影响
CVSS Information
N/A
Vulnerability Type
N/A