Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rhw6-mfvp-rwr4

Опубликовано: 21 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

A directory traversal vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to read arbitrary files from the file system. Please note: an attacker must first obtain compromised access to the target Deep Security Manager (DSM) or the target agent must be not yet activated or configured in order to exploit this vulnerability.

A directory traversal vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to read arbitrary files from the file system. Please note: an attacker must first obtain compromised access to the target Deep Security Manager (DSM) or the target agent must be not yet activated or configured in order to exploit this vulnerability.

EPSS

Процентиль: 79%
0.01216
Низкий

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
nvd
около 4 лет назад

A directory traversal vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to read arbitrary files from the file system. Please note: an attacker must first obtain compromised access to the target Deep Security Manager (DSM) or the target agent must be not yet activated or configured in order to exploit this vulnerability.

EPSS

Процентиль: 79%
0.01216
Низкий

Дефекты

CWE-22