LOW · 3.5

CVE-2014-0347

The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31, Web Security 7.7.3 before Hotfix 31, Web Security Gateway 7.7.3 before Hotfix ...

Vulnerability Description

The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31, Web Security 7.7.3 before Hotfix 31, Web Security Gateway 7.7.3 before Hotfix 31, and Web Security Gateway Anywhere 7.7.3 before Hotfix 31 allows remote authenticated users to read cleartext passwords by replacing type="password" with type="text" in an INPUT element in the (1) Log Database or (2) User Directories component.

CVSS Score

3.5

LOW

AV:N/AC:M/Au:S/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
WebsenseTriton Unified Security Center7.7.3
WebsenseTriton Web Filter7.7.3
WebsenseTriton Web Security7.7.3
WebsenseTriton Web Security Gateway7.7.3
WebsenseTriton Web Security Gateway Anywhere7.7.3

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-0347?

CVE-2014-0347 is a vulnerability with a CVSS score of 3.5 (LOW). The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31, Web Security 7.7.3 before Hotfix 31, Web Security Gateway 7.7.3 before Hotfix ...

How severe is CVE-2014-0347?

CVE-2014-0347 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-0347?

Check the references section above for vendor advisories and patch information. Affected products include: Websense Triton Unified Security Center, Websense Triton Web Filter, Websense Triton Web Security, Websense Triton Web Security Gateway, Websense Triton Web Security Gateway Anywhere.