CVE-2012-4604: Medium severity websense web security vulnerability
The TRITON management console in Websense Web Security before 7.6 Hotfix 24 allows remote attackers to bypass authentication and read arbitrary reports via a crafted uid field, in conjunction with a crafted userRoles field, in a cookie, as demonstrated by a request to explorerwse/favorites.exe.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4604?
CVE-2012-4604 is rated as a high-severity vulnerability that allows remote attackers to bypass authentication.
How do I fix CVE-2012-4604?
To fix CVE-2012-4604, update Websense Web Security to version 7.6 Hotfix 24 or later.
Which versions of Websense Web Security are affected by CVE-2012-4604?
CVE-2012-4604 affects Websense Web Security versions prior to 7.6 Hotfix 24, including versions 6.3.0 to 7.5.1.
What type of attack does CVE-2012-4604 describe?
CVE-2012-4604 describes an authentication bypass vulnerability that could lead to unauthorized access to reports.
Is there a public exploit available for CVE-2012-4604?
Yes, there are indications of public exploits that target the authentication bypass in CVE-2012-4604.