PT-2012-1268 · Websense · Websense Enterprise

Publicado

2012-08-23

·

Atualizado

2017-08-29

·

CVE-2008-7312

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Websense Enterprise versions 5.2 through 6.3
Description The issue allows remote attackers to bypass filtering via an HTTP request. This is because the Filtering Service does not consider the IP address during URL categorization. For example, a request to a compromised server associated with a specific IP address can be used to demonstrate this bypass.
Recommendations For Websense Enterprise versions 5.2 through 6.3, consider restricting access to the Filtering Service until a patch is available. As a temporary workaround, restrict the use of HTTP requests to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-7312

Produtos afetados

Websense Enterprise