Description
The default configuration of Apache Tomcat in Websense Manager in Websense Web Security 7.0 and Web Filter 7.0 allows connections to TCP port 1812 from arbitrary source IP addresses, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via UTF-7 text to the 404 error page of a Project Woodstock service on this port.
Published: 2012-08-23
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2009-5075 The default configuration of Apache Tomcat in Websense Manager in Websense Web Security 7.0 and Web Filter 7.0 allows connections to TCP port 1812 from arbitrary source IP addresses, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via UTF-7 text to the 404 error page of a Project Woodstock service on this port.
History

No history.

Subscriptions

Websense Websense Web Filter Websense Web Security
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-16T18:39:06.076Z

Reserved: 2012-08-23T00:00:00.000Z

Link: CVE-2009-5120

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2012-08-23T10:32:14.343

Modified: 2026-04-29T01:13:23.040

Link: CVE-2009-5120

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses