4.9

CVE-2019-9488

Trend Micro Deep Security Manager (10.x, 11.x) and Vulnerability Protection (2.0) are vulnerable to a XML External Entity Attack. However, for the attack to be possible, the attacker must have root/admin access to a protected host which is authorized to communicate with the Deep Security Manager (DSM).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Deep Security Manager Version 10.0 Update -
Trendmicro ≫ Deep Security Manager Version 10.0 Update u1
Trendmicro ≫ Deep Security Manager Version 10.0 Update u10
Trendmicro ≫ Deep Security Manager Version 10.0 Update u11
Trendmicro ≫ Deep Security Manager Version 10.0 Update u12
Trendmicro ≫ Deep Security Manager Version 10.0 Update u13
Trendmicro ≫ Deep Security Manager Version 10.0 Update u14
Trendmicro ≫ Deep Security Manager Version 10.0 Update u15
Trendmicro ≫ Deep Security Manager Version 10.0 Update u16
Trendmicro ≫ Deep Security Manager Version 10.0 Update u17
Trendmicro ≫ Deep Security Manager Version 10.0 Update u18
Trendmicro ≫ Deep Security Manager Version 10.0 Update u19
Trendmicro ≫ Deep Security Manager Version 10.0 Update u2
Trendmicro ≫ Deep Security Manager Version 10.0 Update u3
Trendmicro ≫ Deep Security Manager Version 10.0 Update u4
Trendmicro ≫ Deep Security Manager Version 10.0 Update u5
Trendmicro ≫ Deep Security Manager Version 10.0 Update u6
Trendmicro ≫ Deep Security Manager Version 10.0 Update u7
Trendmicro ≫ Deep Security Manager Version 10.0 Update u8
Trendmicro ≫ Deep Security Manager Version 10.0 Update u9
Trendmicro ≫ Deep Security Manager Version 11.0 Update -
Trendmicro ≫ Deep Security Manager Version 11.0 Update u1
Trendmicro ≫ Deep Security Manager Version 11.0 Update u2
Trendmicro ≫ Deep Security Manager Version 11.0 Update u3
Trendmicro ≫ Deep Security Manager Version 11.0 Update u4
Trendmicro ≫ Deep Security Manager Version 11.0 Update u5
Trendmicro ≫ Deep Security Manager Version 11.0 Update u6
Trendmicro ≫ Deep Security Manager Version 11.0 Update u7
Trendmicro ≫ Deep Security Manager Version 11.3 Update -
Trendmicro ≫ Vulnerability Protection Version 2.0 Update -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.23% 0.649
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

https://success.trendmicro.com/solution/1122900
Patch
Vendor Advisory