CVE-2012-4604

EUVD-2012-4529
The TRITON management console in Websense Web Security before 7.6 Hotfix 24 allows remote attackers to bypass authentication and read arbitrary reports via a crafted uid field, in conjunction with a crafted userRoles field, in a cookie, as demonstrated by a request to explorer_wse/favorites.exe.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
Affected Products (NVD)
VendorProductVersion
websensewebsense_web_security
𝑥
≤ 7.6
websensewebsense_web_security
6.3.0
websensewebsense_web_security
6.3.1
websensewebsense_web_security
6.3.2
websensewebsense_web_security
6.3.3
websensewebsense_web_security
7.0
websensewebsense_web_security
7.1
websensewebsense_web_security
7.1.1
websensewebsense_web_security
7.5
websensewebsense_web_security
7.5.1
𝑥
= Vulnerable software versions