CVE-2014-0347
Last modified
CVE-2014-0347 is a vulnerability of currently unknown severity. The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31, Web Security 7.7.3 before Hotfix 31, Web Security Gateway 7.7.3 before Hotfix 31, and Web Security Gateway Anywhere 7.7.3 before Hotfix 31 allows remote authenticated users to read cleartext passwords by replacing type="password" with type="text" in an INPUT element in the (1) Log Database or (2) User Directories component.. EPSS estimates a 1.34% chance of exploitation in the next 30 days.
Description
The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31, Web Security 7.7.3 before Hotfix 31, Web Security Gateway 7.7.3 before Hotfix 31, and Web Security Gateway Anywhere 7.7.3 before Hotfix 31 allows remote authenticated users to read cleartext passwords by replacing type="password" with type="text" in an INPUT element in the (1) Log Database or (2) User Directories component.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Websense | Triton Unified Security Center | 7.7.3 |
| Websense | Triton Web Filter | 7.7.3 |
| Websense | Triton Web Security | 7.7.3 |
| Websense | Triton Web Security Gateway | 7.7.3 |
| Websense | Triton Web Security Gateway Anywhere | 7.7.3 |
References
- http://www.kb.cert.org/vuls/id/568252US Government Resource
- http://www.kb.cert.org/vuls/id/568252US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-0347?
How severe is CVE-2014-0347?
How do I fix CVE-2014-0347?
Are you affected by CVE-2014-0347?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
