Vulnerability Description
The TRITON management console in Websense Web Security before 7.6 Hotfix 24 allows remote attackers to bypass authentication and read arbitrary reports via a crafted uid field, in conjunction with a crafted userRoles field, in a cookie, as demonstrated by a request to explorer_wse/favorites.exe.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Websense | Websense Web Security | <= 7.6 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/archive/1/522530Exploit
- http://www.securityfocus.com/archive/1/522530Exploit
FAQ
What is CVE-2012-4604?
CVE-2012-4604 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The TRITON management console in Websense Web Security before 7.6 Hotfix 24 allows remote attackers to bypass authentication and read arbitrary reports via a crafted uid field, in conjunction with a c...
How severe is CVE-2012-4604?
CVE-2012-4604 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-4604?
Check the references section above for vendor advisories and patch information. Affected products include: Websense Websense Web Security.