4.3
CVE-2009-5119
- EPSS 1.08%
- Veröffentlicht 23.08.2012 10:32:14
- Zuletzt bearbeitet 16.06.2026 23:15:07
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The default configuration of Apache Tomcat in Websense Manager in Websense Web Security 7.0 and Web Filter 7.0 enables weak SSL ciphers in conf/server.xml, which makes it easier for remote attackers to obtain sensitive information by sniffing the network and then conducting a brute-force attack against encrypted session data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Websense ≫ Websense Web Filter Version7.0
Websense ≫ Websense Web Security Version7.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.08% | 0.607 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
http://www.websense.com/support/article/t-kbarticle/v7-Apache-Tomcat-security-vulnerabilities-1258048503850