Vulnerability Description
The Receive Service in Websense Email Security before 7.1 does not recognize domain extensions in the blacklist, which allows remote attackers to bypass intended access restrictions and send e-mail messages via an SMTP session.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Websense | Websense Email Security | <= 7.0 |
Related Weaknesses (CWE)
References
- http://www.websense.com/support/article/t-kbarticle/Release-Notes-for-Websense-E
- http://www.websense.com/support/article/t-kbarticle/Release-Notes-for-Websense-E
FAQ
What is CVE-2009-5131?
CVE-2009-5131 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The Receive Service in Websense Email Security before 7.1 does not recognize domain extensions in the blacklist, which allows remote attackers to bypass intended access restrictions and send e-mail me...
How severe is CVE-2009-5131?
CVE-2009-5131 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-5131?
Check the references section above for vendor advisories and patch information. Affected products include: Websense Websense Email Security.