PT-2015-5864 · Websense · Websense V-Series+1

Cengiz Han Sahin

·

Published

2015-03-26

·

Updated

2018-10-09

·

CVE-2015-2746

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Websense TRITON versions 7.8.3 through 7.8.3 before Hotfix 02 Websense V-Series appliances versions 7.8.3 through 7.8.3 before Hotfix 02
Description The issue concerns the network diagnostics tool CommandLineServlet in the Appliance Manager command line utility. It allows remote authenticated users to execute arbitrary commands via shell metacharacters in the second parameter of a command. This can be demonstrated by the Destination parameter in the ping command, using second parameter with shell metacharacters.
Recommendations For Websense TRITON version 7.8.3, update to version 7.8.4 Hotfix 02 to resolve the issue. For Websense V-Series appliances version 7.8.3, update to version 7.8.4 Hotfix 02 to resolve the issue. As a temporary workaround, consider restricting access to the CommandLineServlet to minimize the risk of exploitation. Avoid using the second parameter in commands until the issue is resolved.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-2746

Affected Products

Websense Triton
Websense V-Series