CVE-2015-2748
medium
CVSS v3
โ
CVSS v4 NEW
โ
VIR risk
5.0
Description
Websense TRITON AP-WEB before 8.0.0 does not properly restrict access to files in explorer_wse/, which allows remote attackers to obtain sensitive information via a direct request to a (1) Web Security incident report or the (2) Explorer configuration (websense.ini) file.
Predictions
Exploit likelihood
20%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| websense | triton_ap_data | {"endIncluding":"7.8.3"} | |
| websense | triton_ap_email | {"endIncluding":"7.8.3"} | |
| websense | triton_ap_web | {"endIncluding":"7.8.3"} | |
| websense | v-series_appliances | {"endIncluding":"7.7"} | |
References
- http://packetstormsecurity.com/files/130901/Websense-Explorer-Missing-Access-Control.html
- http://seclists.org/fulldisclosure/2015/Mar/107
- http://www.securityfocus.com/archive/1/534913/100/0/threaded
- http://www.websense.com/support/article/kbarticle/Vulnerabilities-resolved-in-TRITON-APX-Version-8-0
- https://www.securify.nl/advisory/SFY20140909/missing_access_control_on_websense_explorer_web_folder.html
- http://packetstormsecurity.com/files/130901/Websense-Explorer-Missing-Access-Control.html
- http://seclists.org/fulldisclosure/2015/Mar/107
- http://www.securityfocus.com/archive/1/534913/100/0/threaded
- http://www.websense.com/support/article/kbarticle/Vulnerabilities-resolved-in-TRITON-APX-Version-8-0
- https://www.securify.nl/advisory/SFY20140909/missing_access_control_on_websense_explorer_web_folder.html
CWEs
CWE-200
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.