PT-2009-5993 · Websense · Websense Personal Email Manager+1
Nikolas Sotiriu
·
Published
2009-10-22
·
Updated
2018-10-10
·
CVE-2009-3749
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Websense Personal Email Manager versions prior to 7.1 Hotfix 4
Websense Email Security versions prior to 7.1 Hotfix 4
Description
The issue allows remote attackers to cause a denial of service by sending a HTTP GET request to TCP port 8181 and closing the socket before the service can send a response. This is related to the Web Administrator service.
Recommendations
For Websense Personal Email Manager versions prior to 7.1 Hotfix 4, apply Hotfix 4 to resolve the issue.
For Websense Email Security versions prior to 7.1 Hotfix 4, apply Hotfix 4 to resolve the issue.
As a temporary workaround, consider restricting access to TCP port 8181 to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Websense Email Security
Websense Personal Email Manager