CVE-2015-2746: Command Injection
The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON 7.8.3 and V-Series appliances before 7.8.4 Hotfix 02 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the "second" parameter of a command, as demonstrated by the Destination parameter in the ping command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2746?
CVE-2015-2746 is classified as a high severity vulnerability due to its potential for remote command execution.
How do I fix CVE-2015-2746?
To fix CVE-2015-2746, upgrade to Websense TRITON version 7.8.4 Hotfix 02 or later.
Who is affected by CVE-2015-2746?
CVE-2015-2746 affects Websense TRITON 7.8.3 and V-Series appliances up to version 7.7.
What type of vulnerability is CVE-2015-2746?
CVE-2015-2746 is a command injection vulnerability.
Can CVE-2015-2746 be exploited remotely?
Yes, CVE-2015-2746 can be exploited by remote authenticated users.