RSS   Vulnerabilities for 'Interscan web security suite'   RSS

2009-02-17
 
CVE-2009-0613

CWE-264
 

 
Trend Micro InterScan Web Security Suite (IWSS) 3.1 before build 1237 allows remote authenticated Auditor and Report Only users to bypass intended permission settings, and modify the system configuration, via requests to unspecified JSP pages.

 
 
CVE-2009-0612

CWE-200
 

 
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 3.x and InterScan Web Security Suite (IWSS) 3.x, when basic authorization is enabled on the standalone proxy, forwards the Proxy-Authorization header from Windows Media Player, which allows remote web servers to obtain credentials by offering a media stream and then capturing this header.

 

 >>> Vendor: Trendmicro 49 Products
Internet security
Officescan
Trend micro internet security
Housecall
Trend micro antivirus
Internet security 2010
Interscan messaging security suite
Interscan messaging security virtual appliance
Interscan web security virtual appliance
Tmeext.sys
Maximum security
Premium security
Antivirus+
Mobile security
Threat discovery appliance
Serverprotect
Deep discovery director
Control manager
Deep discovery email inspector
Trend micro control manager
Smart protection server
Web security virtual appliance
Officescan xg
Scanmail
Encryption for email
Email encryption gateway
Endpoint application control
Antivirus + security
Officescan monthly
Interscan web security suite
Deep discovery inspector
Dr. safety
Apex one
Business security
Password manager
Antivirus + security 2019
Internet security 2019
Maximum security 2019
Micro security 2019
Premium security 2019
Ransom buster
Deep security manager
Vulnerability protection
Housecall for home networks
Deep security as a service
Antivirus
Worry-free business security
Home network security
Officescan business security


Copyright 2021, cxsecurity.com

 

Back to Top