ID

VAR-201208-0647


CVE

CVE-2011-5102


TITLE

plural Websense Product TRITON Management console command execution vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2012-003850

DESCRIPTION

The Investigative Reports web interface in the TRITON management console in Websense Web Security 7.1 before Hotfix 109, 7.1.1 before Hotfix 06, 7.5 before Hotfix 78, 7.5.1 before Hotfix 12, 7.6 before Hotfix 24, and 7.6.2 before Hotfix 12; Web Filter; Web Security Gateway; and Web Security Gateway Anywhere allows remote attackers to execute commands via unspecified vectors. A remote attacker could exploit this vulnerability to execute arbitrary commands through an unknown vector

Trust: 1.98

sources: NVD: CVE-2011-5102 // JVNDB: JVNDB-2012-003850 // BID: 78338 // VULHUB: VHN-53047

AFFECTED PRODUCTS

vendor:websensemodel:web securityscope:eqversion:7.6.2

Trust: 1.9

vendor:websensemodel:web securityscope:eqversion:7.5.1

Trust: 1.9

vendor:websensemodel:web securityscope:eqversion:7.1.1

Trust: 1.9

vendor:websensemodel:web securityscope:eqversion:7.6

Trust: 1.9

vendor:websensemodel:web securityscope:eqversion:7.5

Trust: 1.9

vendor:websensemodel:web securityscope:eqversion:7.1

Trust: 1.9

vendor:websensemodel:web filterscope:eqversion:*

Trust: 1.0

vendor:websensemodel:web security gatewayscope:eqversion:*

Trust: 1.0

vendor:websensemodel:web security gateway anywherescope:eqversion:*

Trust: 1.0

vendor:web sensemodel:websense web security gateway anywherescope: - version: -

Trust: 0.8

vendor:web sensemodel:websense web securityscope:ltversion:7.5.1

Trust: 0.8

vendor:web sensemodel:websense web security gatewayscope: - version: -

Trust: 0.8

vendor:web sensemodel:websense web securityscope:eqversion:7.1.1 hotfix 06

Trust: 0.8

vendor:web sensemodel:websense web securityscope:eqversion:7.1 hotfix 109

Trust: 0.8

vendor:web sensemodel:websense web securityscope:ltversion:7.1

Trust: 0.8

vendor:web sensemodel:websense web securityscope:eqversion:7.5 hotfix 78

Trust: 0.8

vendor:web sensemodel:websense web securityscope:ltversion:7.6

Trust: 0.8

vendor:web sensemodel:websense web securityscope:eqversion:7.6 hotfix 24

Trust: 0.8

vendor:web sensemodel:websense web securityscope:ltversion:7.6.2

Trust: 0.8

vendor:web sensemodel:websense web securityscope:ltversion:7.5

Trust: 0.8

vendor:web sensemodel:websense web securityscope:ltversion:7.1.1

Trust: 0.8

vendor:web sensemodel:websense web filterscope: - version: -

Trust: 0.8

vendor:web sensemodel:websense web securityscope:eqversion:7.6.2 hotfix 12

Trust: 0.8

vendor:web sensemodel:websense web securityscope:eqversion:7.5.1 hotfix 12

Trust: 0.8

vendor:websensemodel:web security gateway anywherescope: - version: -

Trust: 0.6

vendor:websensemodel:web filterscope: - version: -

Trust: 0.6

vendor:websensemodel:web security gatewayscope: - version: -

Trust: 0.6

vendor:websensemodel:web security gateway anywherescope:eqversion:0

Trust: 0.3

vendor:websensemodel:web security gatewayscope:eqversion:0

Trust: 0.3

vendor:websensemodel:web filterscope:eqversion:0

Trust: 0.3

sources: BID: 78338 // JVNDB: JVNDB-2012-003850 // CNNVD: CNNVD-201208-447 // NVD: CVE-2011-5102

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2011-5102
value: HIGH

Trust: 1.0

NVD: CVE-2011-5102
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201208-447
value: HIGH

Trust: 0.6

VULHUB: VHN-53047
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2011-5102
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-53047
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-53047 // JVNDB: JVNDB-2012-003850 // CNNVD: CNNVD-201208-447 // NVD: CVE-2011-5102

PROBLEMTYPE DATA

problemtype:CWE-264

Trust: 1.9

sources: VULHUB: VHN-53047 // JVNDB: JVNDB-2012-003850 // NVD: CVE-2011-5102

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201208-447

TYPE

permissions and access control

Trust: 0.6

sources: CNNVD: CNNVD-201208-447

CONFIGURATIONS

sources: JVNDB: JVNDB-2012-003850

PATCH

title:000005539url:http://www.websense.com/support/article/kbarticle/v7-6-About-Hotfix-24-for-Websense-Web-Security-Web-Filter-Web-Security-Gateway-and-Web-Security-Gateway-Anywhere

Trust: 0.8

title:000005499url:http://www.websense.com/support/article/kbarticle/v7-6-2-About-Hotfix-12-for-Websense-Web-Security-Websense-Web-Filter-and-Web-Security-Gateway

Trust: 0.8

title:000005537url:http://www.websense.com/support/article/kbarticle/v7-6-2-About-Hotfix-12-for-Websense-Web-Security-Web-Filter-Web-Security-Gateway-and-Web-Security-Gateway-Anywhere

Trust: 0.8

title:000005597url:http://www.websense.com/support/article/kbarticle/v7-5-About-Hotfix-78-for-Websense-Web-Security-Web-Filter-Web-Security-Gateway-and-Web-Security-Gateway-Anywhere

Trust: 0.8

title:000005536url:http://www.websense.com/support/article/kbarticle/v7-5-1-About-Hotfix-12-for-Websense-Web-Security-Web-Filter-Web-Security-Gateway-and-Web-Security-Gateway-Anywhere

Trust: 0.8

title:000005550url:http://www.websense.com/support/article/kbarticle/v7-1-About-Hotfix-109-for-Websense-Web-Security-Web-Filter-and-Web-Security-Gateway

Trust: 0.8

title:000005538url:http://www.websense.com/support/article/kbarticle/v7-1-1-About-Hotfix-06-for-Web-Security-Web-Filter-and-Web-Security-Gateway

Trust: 0.8

title:000005500url:http://www.websense.com/support/article/kbarticle/v7-6-About-Hotfix-24-for-Websense-Web-Security-Websense-Web-Filter-and-Web-Security-Gateway

Trust: 0.8

sources: JVNDB: JVNDB-2012-003850

EXTERNAL IDS

db:NVDid:CVE-2011-5102

Trust: 2.8

db:JVNDBid:JVNDB-2012-003850

Trust: 0.8

db:CNNVDid:CNNVD-201208-447

Trust: 0.7

db:BIDid:78338

Trust: 0.4

db:VULHUBid:VHN-53047

Trust: 0.1

sources: VULHUB: VHN-53047 // BID: 78338 // JVNDB: JVNDB-2012-003850 // CNNVD: CNNVD-201208-447 // NVD: CVE-2011-5102

REFERENCES

url:http://www.websense.com/support/article/kbarticle/v7-1-1-about-hotfix-06-for-web-security-web-filter-and-web-security-gateway

Trust: 2.0

url:http://www.websense.com/support/article/kbarticle/v7-1-about-hotfix-109-for-websense-web-security-web-filter-and-web-security-gateway

Trust: 2.0

url:http://www.websense.com/support/article/kbarticle/v7-5-1-about-hotfix-12-for-websense-web-security-web-filter-web-security-gateway-and-web-security-gateway-anywhere

Trust: 2.0

url:http://www.websense.com/support/article/kbarticle/v7-5-about-hotfix-78-for-websense-web-security-web-filter-web-security-gateway-and-web-security-gateway-anywhere

Trust: 2.0

url:http://www.websense.com/support/article/kbarticle/v7-6-2-about-hotfix-12-for-websense-web-security-web-filter-web-security-gateway-and-web-security-gateway-anywhere

Trust: 2.0

url:http://www.websense.com/support/article/kbarticle/v7-6-2-about-hotfix-12-for-websense-web-security-websense-web-filter-and-web-security-gateway

Trust: 2.0

url:http://www.websense.com/support/article/kbarticle/v7-6-about-hotfix-24-for-websense-web-security-web-filter-web-security-gateway-and-web-security-gateway-anywhere

Trust: 2.0

url:http://www.websense.com/support/article/kbarticle/v7-6-about-hotfix-24-for-websense-web-security-websense-web-filter-and-web-security-gateway

Trust: 2.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2011-5102

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2011-5102

Trust: 0.8

sources: VULHUB: VHN-53047 // BID: 78338 // JVNDB: JVNDB-2012-003850 // CNNVD: CNNVD-201208-447 // NVD: CVE-2011-5102

CREDITS

Unknown

Trust: 0.3

sources: BID: 78338

SOURCES

db:VULHUBid:VHN-53047
db:BIDid:78338
db:JVNDBid:JVNDB-2012-003850
db:CNNVDid:CNNVD-201208-447
db:NVDid:CVE-2011-5102

LAST UPDATE DATE

2025-04-11T23:04:12.412000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-53047date:2012-08-23T00:00:00
db:BIDid:78338date:2012-08-23T00:00:00
db:JVNDBid:JVNDB-2012-003850date:2012-08-24T00:00:00
db:CNNVDid:CNNVD-201208-447date:2012-08-24T00:00:00
db:NVDid:CVE-2011-5102date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:VULHUBid:VHN-53047date:2012-08-23T00:00:00
db:BIDid:78338date:2012-08-23T00:00:00
db:JVNDBid:JVNDB-2012-003850date:2012-08-24T00:00:00
db:CNNVDid:CNNVD-201208-447date:2012-08-24T00:00:00
db:NVDid:CVE-2011-5102date:2012-08-23T10:32:14.873