CVE-2012-4604

The TRITON management console in Websense Web Security before 7.6 Hotfix 24 allows remote attackers to bypass authentication and read arbitrary reports via a crafted uid field, in conjunction with a crafted userRoles field, in a cookie, as demonstrated by a request to explorer_wse/favorites.exe.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 39%
VendorProductVersion
websensewebsense_web_security
𝑥
≤ 7.6
websensewebsense_web_security
6.3.0
websensewebsense_web_security
6.3.1
websensewebsense_web_security
6.3.2
websensewebsense_web_security
6.3.3
websensewebsense_web_security
7.0
websensewebsense_web_security
7.1
websensewebsense_web_security
7.1.1
websensewebsense_web_security
7.5
websensewebsense_web_security
7.5.1
𝑥
= Vulnerable software versions