PT-2007-2595 · Trend Micro · Trend Micro Serverprotect For Linux
Published
2007-02-28
·
Updated
2011-03-08
·
CVE-2007-1168
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Trend Micro ServerProtect for Linux (SPLX) versions 1.25, 1.3, and 2.5 before 20070216
Description
The issue allows remote attackers to access arbitrary web pages and reconfigure the product via HTTP requests with the
splx 2376 info cookie to the web interface port (14942/tcp).Recommendations
For versions 1.25, 1.3, and 2.5 before 20070216, consider restricting access to the web interface port 14942/tcp until a fix is applied.
As a temporary workaround, avoid using the
splx 2376 info cookie in HTTP requests to the web interface until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trend Micro Serverprotect For Linux