PT-2015-5864 · Websense · Websense V-Series+1
Cengiz Han Sahin
·
Published
2015-03-26
·
Updated
2018-10-09
·
CVE-2015-2746
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Websense TRITON versions 7.8.3 through 7.8.3 before Hotfix 02
Websense V-Series appliances versions 7.8.3 through 7.8.3 before Hotfix 02
Description
The issue concerns the network diagnostics tool CommandLineServlet in the Appliance Manager command line utility. It allows remote authenticated users to execute arbitrary commands via shell metacharacters in the
second parameter of a command. This can be demonstrated by the Destination parameter in the ping command, using second parameter with shell metacharacters.Recommendations
For Websense TRITON version 7.8.3, update to version 7.8.4 Hotfix 02 to resolve the issue.
For Websense V-Series appliances version 7.8.3, update to version 7.8.4 Hotfix 02 to resolve the issue.
As a temporary workaround, consider restricting access to the CommandLineServlet to minimize the risk of exploitation.
Avoid using the
second parameter in commands until the issue is resolved.Exploit
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Websense Triton
Websense V-Series