CVE-2015-2748: Infoleak
Websense TRITON AP-WEB before 8.0.0 does not properly restrict access to files in explorerwse/, which allows remote attackers to obtain sensitive information via a direct request to a (1) Web Security incident report or the (2) Explorer configuration (websense.ini) file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2748?
CVE-2015-2748 is rated as a medium severity vulnerability due to improper access controls.
How do I fix CVE-2015-2748?
To fix CVE-2015-2748, upgrade to Websense TRITON AP-WEB version 8.0.0 or later.
What type of information can be exposed by CVE-2015-2748?
CVE-2015-2748 can expose sensitive information such as Web Security incident reports and the explorer configuration file.
Which Websense products are affected by CVE-2015-2748?
CVE-2015-2748 affects Websense TRITON AP-WEB, AP-DATA, AP-EMAIL, and V-series appliances up to specific versions.
Can CVE-2015-2748 be exploited remotely?
Yes, CVE-2015-2748 allows remote attackers to exploit the vulnerability through direct requests.