Vulnerability Description
Websense TRITON V-Series appliances before 7.8.3 Hotfix 03 and 7.8.4 before Hotfix 01 allow remote administrators to read arbitrary files and obtain passwords via a crafted path.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Websense | V-Series Appliances | <= 7.7 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/73417
- http://www.websense.com/support/article/kbarticle/v7-8-3-About-Hotfix-03-for-V-SVendor Advisory
- http://www.websense.com/support/article/kbarticle/v7-8-4-About-Hotfix-01-for-V-SVendor Advisory
- http://www.securityfocus.com/bid/73417
- http://www.websense.com/support/article/kbarticle/v7-8-3-About-Hotfix-03-for-V-SVendor Advisory
- http://www.websense.com/support/article/kbarticle/v7-8-4-About-Hotfix-01-for-V-SVendor Advisory
FAQ
What is CVE-2014-9712?
CVE-2014-9712 is a vulnerability with a CVSS score of 4.0 (MEDIUM). Websense TRITON V-Series appliances before 7.8.3 Hotfix 03 and 7.8.4 before Hotfix 01 allow remote administrators to read arbitrary files and obtain passwords via a crafted path.
How severe is CVE-2014-9712?
CVE-2014-9712 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-9712?
Check the references section above for vendor advisories and patch information. Affected products include: Websense V-Series Appliances.