ProxySG and ASG CVE-2016-9097 Remote Authorization Bypass Vulnerability
BID:101530
Info
ProxySG and ASG CVE-2016-9097 Remote Authorization Bypass Vulnerability
| Bugtraq ID: | 101530 |
| Class: | Access Validation Error |
| CVE: |
CVE-2016-9097 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 26 2017 12:00AM |
| Updated: | Dec 19 2017 08:00PM |
| Credit: | Jakub Palaczynski and Pawel Bartunek. |
| Vulnerable: |
Blue Coat Systems ProxySG 6.5.4 Blue Coat Systems ProxySG 6.5.3 6 Blue Coat Systems ProxySG 6.5.3 5 Blue Coat Systems ProxySG 6.7 Blue Coat Systems ProxySG 6.6 Blue Coat Systems ProxySG 6.5.8.8 Blue Coat Systems ProxySG 6.5.7.3 Blue Coat Systems ProxySG 6.5.5.7 Blue Coat Systems ProxySG 6.5.5.4 Blue Coat Systems ProxySG 6.5.1.1 Blue Coat Systems ProxySG 6.5 Blue Coat Systems Advanced Secure Gateway 6.6 |
| Not Vulnerable: |
Blue Coat Systems ProxySG 6.7.1.2 Blue Coat Systems ProxySG 6.6.5.8 Blue Coat Systems ProxySG 6.5.10.6 Blue Coat Systems Advanced Secure Gateway 6.6.5.8 |
Discussion
ProxySG and ASG CVE-2016-9097 Remote Authorization Bypass Vulnerability
ProxySG and ASG are prone to an authorization-bypass vulnerability.
Attackers can exploit this issue to gain unauthorized access and obtain sensitive information or elevate privileges. This may aid in further attacks.
The following products are affected:
Blue Coat Systems ASG 6.6 prior to 6.6.5.8 is vulnerable.
Blue Coat Systems ProxySG 6.5 prior to 6.5.10.6, 6.6 prior to 6.6.5.8, and 6.7 prior to 6.7.1.2 are vulnerable.
ProxySG and ASG are prone to an authorization-bypass vulnerability.
Attackers can exploit this issue to gain unauthorized access and obtain sensitive information or elevate privileges. This may aid in further attacks.
The following products are affected:
Blue Coat Systems ASG 6.6 prior to 6.6.5.8 is vulnerable.
Blue Coat Systems ProxySG 6.5 prior to 6.5.10.6, 6.6 prior to 6.6.5.8, and 6.7 prior to 6.7.1.2 are vulnerable.
Exploit / POC
ProxySG and ASG CVE-2016-9097 Remote Authorization Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
ProxySG and ASG CVE-2016-9097 Remote Authorization Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
ProxySG and ASG CVE-2016-9097 Remote Authorization Bypass Vulnerability
References:
References:
- Blue Coat ProxySG product page (Blue Coat)
- BlueCoat Homepage (BlueCoat)
- SA146: Improper User Authorization in ProxySG and ASG (Symantec)