PT-2017-10036 · Trend Micro · Trend Micro Interscan Web Security Virtual Appliance
Published
2017-02-21
·
Updated
2017-07-25
·
CVE-2016-9269
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Trend Micro Interscan Web Security Virtual Appliance (IWSVA) versions 6.5-SP2 Build Linux 1707 and earlier
Description
The issue allows authenticated, remote users with least privileges to run arbitrary commands on the system as root via Patch Update functionality in the
com.trend.iwss.gui.servlet.ManagePatches component.Recommendations
For versions 6.5-SP2 Build Linux 1707 and earlier, update to Version 6.5 CP 1737 to resolve the issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trend Micro Interscan Web Security Virtual Appliance