CVE-2009-5120: XSS
The default configuration of Apache Tomcat in Websense Manager in Websense Web Security 7.0 and Web Filter 7.0 allows connections to TCP port 1812 from arbitrary source IP addresses, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via UTF-7 text to the 404 error page of a Project Woodstock service on this port.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-5120?
CVE-2009-5120 has a severity rating that indicates it poses a risk for cross-site scripting (XSS) attacks.
How do I fix CVE-2009-5120?
To fix CVE-2009-5120, configure Apache Tomcat to restrict access to TCP port 1812 to trusted IP addresses only.
What software is affected by CVE-2009-5120?
CVE-2009-5120 affects Websense Web Security 7.0 and Websense Web Filter 7.0.
Can CVE-2009-5120 lead to data loss?
Exploitation of CVE-2009-5120 could potentially lead to data exposure or manipulation through XSS attacks.
What type of attack does CVE-2009-5120 facilitate?
CVE-2009-5120 facilitates cross-site scripting (XSS) attacks due to improper configuration of Apache Tomcat.