RULE(RULE ID:311287)

Rule General Information
Release Date: 2015-03-09
Rule Name: Sophos Web Appliance change_password Admin Password Privilege Escalation -4 (CVE-2014-2849)
Severity:
CVE ID:
Rule Protection Details
Description: A privilege escalation vulnerability exists in Sophos Web Appliance. The vulnerability is due to errors in achange_password request when handling user input.
Impact: Privilege escalation
Affected OS: Windows, Other Unix, Linux
Reference: CVE-2014-2850
SecurityFocusBID:66734
OSVDB:105636
Solutions
Update vendor's patch.