4.9
CVE-2019-9488
- EPSS 1.23%
- Veröffentlicht 11.09.2019 18:15:10
- Zuletzt bearbeitet 21.11.2024 04:51:42
- Erkennungen
Trend Micro Deep Security Manager (10.x, 11.x) and Vulnerability Protection (2.0) are vulnerable to a XML External Entity Attack. However, for the attack to be possible, the attacker must have root/admin access to a protected host which is authorized to communicate with the Deep Security Manager (DSM).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Deep Security Manager Version 10.0 Update -
Trendmicro ≫ Deep Security Manager Version 10.0 Update u1
Trendmicro ≫ Deep Security Manager Version 10.0 Update u10
Trendmicro ≫ Deep Security Manager Version 10.0 Update u11
Trendmicro ≫ Deep Security Manager Version 10.0 Update u12
Trendmicro ≫ Deep Security Manager Version 10.0 Update u13
Trendmicro ≫ Deep Security Manager Version 10.0 Update u14
Trendmicro ≫ Deep Security Manager Version 10.0 Update u15
Trendmicro ≫ Deep Security Manager Version 10.0 Update u16
Trendmicro ≫ Deep Security Manager Version 10.0 Update u17
Trendmicro ≫ Deep Security Manager Version 10.0 Update u18
Trendmicro ≫ Deep Security Manager Version 10.0 Update u19
Trendmicro ≫ Deep Security Manager Version 10.0 Update u2
Trendmicro ≫ Deep Security Manager Version 10.0 Update u3
Trendmicro ≫ Deep Security Manager Version 10.0 Update u4
Trendmicro ≫ Deep Security Manager Version 10.0 Update u5
Trendmicro ≫ Deep Security Manager Version 10.0 Update u6
Trendmicro ≫ Deep Security Manager Version 10.0 Update u7
Trendmicro ≫ Deep Security Manager Version 10.0 Update u8
Trendmicro ≫ Deep Security Manager Version 10.0 Update u9
Trendmicro ≫ Deep Security Manager Version 11.0 Update -
Trendmicro ≫ Deep Security Manager Version 11.0 Update u1
Trendmicro ≫ Deep Security Manager Version 11.0 Update u2
Trendmicro ≫ Deep Security Manager Version 11.0 Update u3
Trendmicro ≫ Deep Security Manager Version 11.0 Update u4
Trendmicro ≫ Deep Security Manager Version 11.0 Update u5
Trendmicro ≫ Deep Security Manager Version 11.0 Update u6
Trendmicro ≫ Deep Security Manager Version 11.0 Update u7
Trendmicro ≫ Deep Security Manager Version 11.3 Update -
Trendmicro ≫ Vulnerability Protection Version 2.0 Update -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.23% | 0.649 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
| NIST | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
CWE-611 Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
https://success.trendmicro.com/solution/1122900