Lucene search

K
cve[email protected]CVE-2010-5144
HistoryOct 03, 2022 - 4:21 p.m.

CVE-2010-5144

2022-10-0316:21:02
CWE-264
web.nvd.nist.gov
22
cve-2010-5144
isapi filter
websense enterprise
websense web security
websense web filter
microsoft isa
microsoft forefront tmg
remote code execution
security vulnerability

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.9 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

57.5%

The ISAPI Filter plug-in in Websense Enterprise, Websense Web Security, and Websense Web Filter 6.3.3 and earlier, when used in conjunction with a Microsoft ISA or Microsoft Forefront TMG server, allows remote attackers to bypass intended filtering and monitoring activities for web traffic via an HTTP Via header.

Affected configurations

NVD
Node
websensewebsenseRange6.3.3-enterprise
OR
websensewebsenseMatch6.3.0-enterprise
OR
websensewebsenseMatch6.3.1-enterprise
Node
websensewebsense_web_securityMatch6.3.0
OR
websensewebsense_web_securityMatch6.3.1
OR
websensewebsense_web_securityMatch6.3.3
Node
websensewebsense_web_filterRange6.3.3
OR
websensewebsense_web_filterMatch6.3.0
OR
websensewebsense_web_filterMatch6.3.1

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.9 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

57.5%

Related for CVE-2010-5144