Overview
Multiple versions of the Trend Micro Deep Discovery threat appliance are vulnerable to cross-site scripting and authentication bypass.
Description
The Trend Micro Deep Discovery platform "enables you to detect, analyze, and respond to today’s stealthy, targeted attacks in real time." It may be deployed on a network as an appliance. The Trend Micro Deep Discovery Threat Appliance version 3.7.1096 is vulnerable to cross-site scripting and authentication bypass. CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') - CVE-2015-2872 |
Impact
An authenticated user without administrator privileges may access and modify certain system configuration settings. An unauthenticated remote user may conduct cross-site scripting attacks. |
Solution
Apply an update
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 5.5 | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Temporal | 4.1 | E:POC/RL:OF/RC:UR |
Environmental | 3.0 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to John Page ("hyp3rlinx") for reporting this vulnerability to us.
This document was written by Garret Wassermann.
Other Information
CVE IDs: | CVE-2015-2872, CVE-2015-2873 |
Date Public: | 2015-08-18 |
Date First Published: | 2015-08-18 |
Date Last Updated: | 2015-08-18 14:52 UTC |
Document Revision: | 38 |