Vulnerability Description
The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31, Web Security 7.7.3 before Hotfix 31, Web Security Gateway 7.7.3 before Hotfix 31, and Web Security Gateway Anywhere 7.7.3 before Hotfix 31 allows remote authenticated users to read cleartext passwords by replacing type="password" with type="text" in an INPUT element in the (1) Log Database or (2) User Directories component.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Websense | Triton Unified Security Center | 7.7.3 |
| Websense | Triton Web Filter | 7.7.3 |
| Websense | Triton Web Security | 7.7.3 |
| Websense | Triton Web Security Gateway | 7.7.3 |
| Websense | Triton Web Security Gateway Anywhere | 7.7.3 |
Related Weaknesses (CWE)
References
- http://www.kb.cert.org/vuls/id/568252US Government Resource
- https://www.websense.com/content/mywebsense-hotfixes.aspx?patchid=894&prodidx=20
- http://www.kb.cert.org/vuls/id/568252US Government Resource
- https://www.websense.com/content/mywebsense-hotfixes.aspx?patchid=894&prodidx=20
FAQ
What is CVE-2014-0347?
CVE-2014-0347 is a vulnerability with a CVSS score of 3.5 (LOW). The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31, Web Security 7.7.3 before Hotfix 31, Web Security Gateway 7.7.3 before Hotfix ...
How severe is CVE-2014-0347?
CVE-2014-0347 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-0347?
Check the references section above for vendor advisories and patch information. Affected products include: Websense Triton Unified Security Center, Websense Triton Web Filter, Websense Triton Web Security, Websense Triton Web Security Gateway, Websense Triton Web Security Gateway Anywhere.