CVE-2009-5119: Medium severity websense web filter vulnerability
The default configuration of Apache Tomcat in Websense Manager in Websense Web Security 7.0 and Web Filter 7.0 enables weak SSL ciphers in conf/server.xml, which makes it easier for remote attackers to obtain sensitive information by sniffing the network and then conducting a brute-force attack against encrypted session data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-5119?
CVE-2009-5119 is considered a medium severity vulnerability due to weak SSL ciphers that allow for sensitive information exposure.
How do I fix CVE-2009-5119?
To fix CVE-2009-5119, you should update the SSL configuration in the conf/server.xml file to disable weak ciphers.
What software is affected by CVE-2009-5119?
CVE-2009-5119 affects Websense Web Security 7.0 and Websense Web Filter 7.0 with default Apache Tomcat configurations.
What does CVE-2009-5119 allow remote attackers to do?
CVE-2009-5119 enables remote attackers to sniff network traffic and conduct brute-force attacks, potentially compromising sensitive information.
Is there a patch available for CVE-2009-5119?
Patches specific to CVE-2009-5119 are not listed, so it is recommended to review the server's SSL configuration and implement best practices.