Vulnerabilities > Websense > Low

DATE CVE VULNERABILITY TITLE RISK
2014-04-12 CVE-2014-0347 Credentials Management vulnerability in Websense products
The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31, Web Security 7.7.3 before Hotfix 31, Web Security Gateway 7.7.3 before Hotfix 31, and Web Security Gateway Anywhere 7.7.3 before Hotfix 31 allows remote authenticated users to read cleartext passwords by replacing type="password" with type="text" in an INPUT element in the (1) Log Database or (2) User Directories component.
network
websense CWE-255
3.5
2012-08-23 CVE-2010-5146 Permissions, Privileges, and Access Controls vulnerability in Websense web Filter and Websense web Security
The Remote Filtering component in Websense Web Security and Web Filter before 7.1 Hotfix 66 allows local users to bypass filtering by (1) renaming the WDC.exe file or (2) deleting driver files.
local
low complexity
websense CWE-264
2.1
2008-10-22 CVE-2008-4646 Credentials Management vulnerability in Websense Enterpise 6.3.2
The Websense Reporter Module in Websense Enterprise 6.3.2 stores the SQL database system administrator password in plaintext in CreateDbInstall.log, which allows local users to gain privileges to the database.
local
low complexity
websense CWE-255
2.1
2006-04-26 CVE-2006-2035 Local Security vulnerability in Websense
Websense, when configured to permit access to the dynamic content category, allows local users to bypass intended blocking of the Uncategorized category by appending a "/?" sequence to a URL.
local
high complexity
websense
3.7