CVE-2010-5148
Estado: ModificadaMedia (5)—
Websense Web Security and Web Filter before 7.1 Hotfix 21 do not set the secure flag for the Encrypted Session (SSL) cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.35%
- Percentil entre todas las CVEs puntuadas: 71
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- NVD-CWE-Other
Referencias
- http://www.websense.com/content/support/library/web/v711/ws711_known_issues/first.aspx
- http://www.websense.com/content/support/library/web/v711/ws711_known_issues/ws711_known_issues.pdf
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78342
- http://www.websense.com/content/support/library/web/v711/ws711_known_issues/first.aspx
- http://www.websense.com/content/support/library/web/v711/ws711_known_issues/ws711_known_issues.pdf
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78342
JSON original (NVD)
Mostrar
{
"id": "CVE-2010-5148",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2012-08-23T10:32:14.767",
"references": [
{
"url": "http://www.websense.com/content/support/library/web/v711/ws711_known_issues/first.aspx",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.websense.com/content/support/library/web/v711/ws711_known_issues/ws711_known_issues.pdf",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78342",
"source": "cve@mitre.org"
},
{
"url": "http://www.websense.com/content/support/library/web/v711/ws711_known_issues/first.aspx",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.websense.com/content/support/library/web/v711/ws711_known_issues/ws711_known_issues.pdf",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78342",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Websense Web Security and Web Filter before 7.1 Hotfix 21 do not set the secure flag for the Encrypted Session (SSL) cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session."
},
{
"lang": "es",
"value": "Websense Web Security y Web Filter anteriores a v7.1 Hotfix 21 no fija el \"flag\" secure para la cookie de sesión Encrypted Session (SSL) en una sesión https, lo que facilita a atacantes remotos la captura de esta cookie interceptándola cuando se transmite dentro de una sesión http.\r\n"
}
],
"lastModified": "2026-06-16T23:26:11.347",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:websense:websense_web_filter:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "53A0539F-BE93-4A7E-88EA-4945427CFA44",
"versionEndIncluding": "7.0"
},
{
"criteria": "cpe:2.3:a:websense:websense_web_security:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "34EA7878-88F6-4A29-8F4E-1164DA81CE6A",
"versionEndIncluding": "7.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}