« Volver al listado

CVE-2010-5144

Estado: ModificadaMedia (4.3)—

The ISAPI Filter plug-in in Websense Enterprise, Websense Web Security, and Websense Web Filter 6.3.3 and earlier, when used in conjunction with a Microsoft ISA or Microsoft Forefront TMG server, allows remote attackers to bypass intended filtering and monitoring activities for web traffic via an HTTP Via header.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-5144",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-08-23T10:32:14.530",
  "references": [
    {
      "url": "http://archives.neohapsis.com/archives/fulldisclosure/2010-05/0376.html",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://mrhinkydink.blogspot.com/2010/05/websense-633-via-bypass.html",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.websense.com/support/article/t-kbarticle/Web-Security-Vulnerability-Microsoft-ISA-Server-Integrations",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://archives.neohapsis.com/archives/fulldisclosure/2010-05/0376.html",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://mrhinkydink.blogspot.com/2010/05/websense-633-via-bypass.html",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.websense.com/support/article/t-kbarticle/Web-Security-Vulnerability-Microsoft-ISA-Server-Integrations",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The ISAPI Filter plug-in in Websense Enterprise, Websense Web Security, and Websense Web Filter 6.3.3 and earlier, when used in conjunction with a Microsoft ISA or Microsoft Forefront TMG server, allows remote attackers to bypass intended filtering and monitoring activities for web traffic via an HTTP Via header."
    },
    {
      "lang": "es",
      "value": "El complemento ISAPI Filter de Websense Enterprise, Websense Web Security y Websense Web Filter v6.3.3 y versiones anteriores, cuando se utiliza junto a Microsoft ISA o con el servidor Microsoft Forefront TMG, permite a atacantes remotos evitar la filtración establecida y monitorizar actividades para el  tráfico web a través de la cabecera HTTP."
    }
  ],
  "lastModified": "2026-06-16T23:26:10.913",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:websense:websense:*:-:enterprise:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C44054E8-5FA5-4210-924E-EB18F942B09F",
              "versionEndIncluding": "6.3.3"
            },
            {
              "criteria": "cpe:2.3:a:websense:websense:6.3.0:-:enterprise:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F204D7A6-92C9-4142-BDFC-FA3682C9A775"
            },
            {
              "criteria": "cpe:2.3:a:websense:websense:6.3.1:-:enterprise:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F9F0A883-DE96-47D7-BBBA-AAA94396B80E"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:websense:websense_web_security:6.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "42C4583F-0A0F-4CD8-BCE5-79D63A00540B"
            },
            {
              "criteria": "cpe:2.3:a:websense:websense_web_security:6.3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7DE86A75-E3BB-446E-B342-F07125B0BFF8"
            },
            {
              "criteria": "cpe:2.3:a:websense:websense_web_security:6.3.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "73886536-436E-4A38-99F8-BFD378D2B4B3"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:websense:websense_web_filter:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C54DEE82-2192-4C7B-A0B5-80D3710AFCAB",
              "versionEndIncluding": "6.3.3"
            },
            {
              "criteria": "cpe:2.3:a:websense:websense_web_filter:6.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B67A75C4-BDD4-4638-B582-A4A151EBBB7A"
            },
            {
              "criteria": "cpe:2.3:a:websense:websense_web_filter:6.3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "292178C0-87D1-4755-BDDF-ED4398DB0BF0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}