VulnerabilityModified
CVE-2009-5122
The Personal Email Manager component in Websense Email Security before 7.2 allows remote attackers to obtain potentially sensitive information from the JBoss status page via an unspecified query.
MEDIUM 5.0EPSS 1.17%
Does this matter?
Lower severity and a low EPSS score (1.17%). Track it; it rarely justifies an emergency change on its own.
Description
The Personal Email Manager component in Websense Email Security before 7.2 allows remote attackers to obtain potentially sensitive information from the JBoss status page via an unspecified query.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.17% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- websense/websense email security
- Source
- cve@mitre.org
References
- http://www.websense.com/content/support/library/email/v72wes/release_notes/WES72_ReleaseNotes.pdfVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78449
- http://www.websense.com/content/support/library/email/v72wes/release_notes/WES72_ReleaseNotes.pdfVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78449
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.