CVE-2015-2748

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
26/03/2015
Last modified:
12/04/2025

Description

Websense TRITON AP-WEB before 8.0.0 does not properly restrict access to files in explorer_wse/, which allows remote attackers to obtain sensitive information via a direct request to a (1) Web Security incident report or the (2) Explorer configuration (websense.ini) file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:websense:triton_ap_data:*:*:*:*:*:*:*:* 7.8.3 (including)
cpe:2.3:a:websense:triton_ap_email:*:*:*:*:*:*:*:* 7.8.3 (including)
cpe:2.3:a:websense:triton_ap_web:*:*:*:*:*:*:*:* 7.8.3 (including)
cpe:2.3:a:websense:v-series_appliances:*:*:*:*:*:*:*:* 7.7 (including)