PT-2019-5833 · Trend Micro · Trend Micro Dr. Safety For Android

Publicado

2019-02-05

·

Atualizado

2019-02-13

·

CVE-2018-18334

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Trend Micro Dr. Safety for Android versions prior to 3.0.1478
Description The issue is related to a bypass of the Same Origin Policy (SOP) in the Private Browser of Trend Micro Dr. Safety for Android, which could allow a remote attacker to obtain sensitive information via crafted JavaScript code. This is due to a lack of protection for service data, enabling an unauthorized access to protected information.
Recommendations For versions prior to 3.0.1478, update to version 3.0.1478 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information until the update is applied.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2021-03295
CVE-2018-18334

Produtos afetados

Trend Micro Dr. Safety For Android