4.3
CVSSv2

CVE-2012-4604

Published: 23/08/2012 Updated: 23/08/2012
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The TRITON management console in Websense Web Security prior to 7.6 Hotfix 24 allows remote malicious users to bypass authentication and read arbitrary reports via a crafted uid field, in conjunction with a crafted userRoles field, in a cookie, as demonstrated by a request to explorer_wse/favorites.exe.

Vulnerable Product Search on Vulmon Subscribe to Product

websense websense web security 7.5

websense websense web security 7.1

websense websense web security

websense websense web security 6.3.3

websense websense web security 6.3.2

websense websense web security 6.3.1

websense websense web security 6.3.0

websense websense web security 7.5.1

websense websense web security 7.1.1

websense websense web security 7.0