Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m5fq-fj2f-7888

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an XML External Entity Processing (XXE) vulnerability which could allow an authenticated administrator to read arbitrary local files. An attacker must already have obtained product administrator/root privileges to exploit this vulnerability.

Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an XML External Entity Processing (XXE) vulnerability which could allow an authenticated administrator to read arbitrary local files. An attacker must already have obtained product administrator/root privileges to exploit this vulnerability.

EPSS

Процентиль: 77%
0.00998
Низкий

Дефекты

CWE-776

Связанные уязвимости

CVSS3: 4.9
nvd
около 5 лет назад

Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an XML External Entity Processing (XXE) vulnerability which could allow an authenticated administrator to read arbitrary local files. An attacker must already have obtained product administrator/root privileges to exploit this vulnerability.

EPSS

Процентиль: 77%
0.00998
Низкий

Дефекты

CWE-776