Check Point Reference: | CPAI-2014-2270 |
Date Published: | 2 Dec 2014 |
Severity: | High |
Last Updated: | Wednesday 03 December, 2014 |
Source: | |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | Web Browsers |
Vulnerability Description | Several web exploitation tools inject payloads that are displayed only when specific conditions are met. This may allow an attacker to reduce the odds of detection and to evade inspection. |
This protection will detect and block attempts to inject conditional payloads onto websites.
In order for the protection to be activated, update your Security Gateway product to the latest IPS update. For information on how to update IPS, go to SBP-2006-05, click on Protection tab and select the version of your choice.
This protection's log will contain the following information:
Attack Name: Web Client Enforcement Violation.
Attack Information: Malicious iFrame Conditional Cookie Injection