10

CVE-2021-36745

A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Network Appliance Filers 5.8, and ServerProtect for Microsoft Windows / Novell Netware 5.8 could allow a remote attacker to bypass authentication on affected installations.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Serverprotect Version 5.8 SwPlatform emc
Trendmicro ≫ Serverprotect Version 5.8 SwPlatform netapp
Trendmicro ≫ Serverprotect Version 5.8 SwPlatform netware
Trendmicro ≫ Serverprotect Version 5.8 SwPlatform windows
Trendmicro ≫ Serverprotect Version 6.0 SwPlatform storage
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.39% 0.95
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-425 Direct Request ('Forced Browsing')

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

https://success.trendmicro.com/jp/solution/000289030
Patch
Vendor Advisory
https://success.trendmicro.com/solution/000289038
Patch
Vendor Advisory
https://www.zerodayinitiative.com/advisories/ZDI-21-1115/
Third Party Advisory
VDB Entry