Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2015-2746

Overview

Vulnerability Score 6.5 6.5
CVE Id CVE-2015-2746
Last Modified 27 Mar 2015 02:09:15
Published 26 Mar 2015 10:59:03
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication SINGLE_INSTANCE

CVE-2015-2746

Summary

The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON 7.8.3 and V-Series appliances before 7.8.4 Hotfix 02 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the "second" parameter of a command, as demonstrated by the Destination parameter in the ping command.

Vulnerable Systems

Application

  • Websense Triton 7.8.3

  • Websense V-series Appliances 7.7


References

MISC - https://www.securify.nl/advisory/SFY20140906/command_injection_vulnerability_in_network_diagnostics_tool_of_websense_appliance_manager.html

CONFIRM - http://www.websense.com/support/article/kbarticle/October-2014-Hotfix-Summary-for-Websense-Solutions

BUGTRAQ - 20150318 Command injection vulnerability in network diagnostics tool of Websense Appliance Manager

MISC - http://packetstormsecurity.com/files/130899/Websense-Appliance-Manager-Command-Injection.html


Last Updated: 27 May 2016 11:08:14